From d0b981757ab416dfd182e6b91e7f9a66132116f9 Mon Sep 17 00:00:00 2001 From: vbenincasa Date: Wed, 9 Jun 2010 19:08:15 +0000 Subject: - Sanitize CSS universal selector from e-mails. Without this fix any message can play with the CSS from entire mail window or mail preview frame. Test case: --- program/include/main.inc | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to 'program') diff --git a/program/include/main.inc b/program/include/main.inc index f98e4311e..e5fe3929b 100644 --- a/program/include/main.inc +++ b/program/include/main.inc @@ -1,4 +1,4 @@ -\s*$)/', - '/(^\s*|,\s*|\}\s*)([a-z0-9\._#][a-z0-9\.\-_]*)/im', + '/(^\s*|,\s*|\}\s*)([a-z0-9\._#\*][a-z0-9\.\-_]*)/im', "/$container_id\s+body/i", ), array( -- cgit v1.2.3