|
COMMAND Instant Web Mail additional POP3 commands and mail headers SYSTEMS AFFECTED Instant Web Mail 0.59 (possibly earlier versions too) PROBLEM Ulf Harnhammar says : An evil link in a mail that passes an additional POP3 command for deleting a mail in the URL that it redirects to, would have Instant Web Mail show the user one mail while deleting another one! http://www.userhost.se/instantwebmail/message.php?id=1%0D%0ADELE+2& SOLUTION Get version 0.60