summaryrefslogtreecommitdiff
path: root/program/steps/mail
diff options
context:
space:
mode:
authoralecpl <alec@alec.pl>2010-02-26 08:06:48 +0000
committeralecpl <alec@alec.pl>2010-02-26 08:06:48 +0000
commitebc619c149f82e9151bbf672cf065447f4d12923 (patch)
treef6d05c8da628e16a772382197d175d6e2f77abdb /program/steps/mail
parent3d0ec7620fafb9acaeac25cab8e81c44a6df2228 (diff)
- Fix CVE-2010-0464: Disable DNS prefetching (#1486449)
Diffstat (limited to 'program/steps/mail')
-rw-r--r--program/steps/mail/get.inc3
1 files changed, 1 insertions, 2 deletions
diff --git a/program/steps/mail/get.inc b/program/steps/mail/get.inc
index cb938c08b..a41925a65 100644
--- a/program/steps/mail/get.inc
+++ b/program/steps/mail/get.inc
@@ -41,6 +41,7 @@ if (!empty($_GET['_uid'])) {
$MESSAGE = new rcube_message(get_input_value('_uid', RCUBE_INPUT_GET));
}
+send_nocacheing_headers();
// show part page
if (!empty($_GET['_frame'])) {
@@ -66,8 +67,6 @@ else if ($pid = get_input_value('_part', RCUBE_INPUT_GET)) {
$browser = new rcube_browser;
- send_nocacheing_headers();
-
// send download headers
if ($_GET['_download']) {
header("Content-Type: application/octet-stream");