Hi! When I give e.g. this url: http://localhost/horde/mimp/mailbox.php?mailbox=/etc%2Fpasswd I can read content of /etc/passwd ... how can I prevet this? With regard Vladimir Volcko