- Fix CVE-2010-0464: Disable DNS prefetching (#1486449)
| | |
| | | CHANGELOG RoundCube Webmail |
| | | =========================== |
| | | |
| | | - Fix CVE-2010-0464: Disable DNS prefetching (#1486449) |
| | | - Fix Received headers to behave better with SpamAssassin (#1486513) |
| | | - Password: Make passwords encoding consistent with core, add 'password_charset' global option (#1486473) |
| | | - Fix adding contacts SQL error on mysql (#1486459) |
| | |
| | | header("Last-Modified: ".gmdate("D, d M Y H:i:s")." GMT"); |
| | | header("Cache-Control: private, must-revalidate, post-check=0, pre-check=0"); |
| | | header("Pragma: no-cache"); |
| | | // Request browser to disable DNS prefetching (CVE-2010-0464) |
| | | header("X-DNS-Prefetch-Control: off"); |
| | | |
| | | // We need to set the following headers to make downloads work using IE in HTTPS mode. |
| | | if (rcube_https_check()) { |
| | |
| | | $MESSAGE = new rcube_message(get_input_value('_uid', RCUBE_INPUT_GET)); |
| | | } |
| | | |
| | | send_nocacheing_headers(); |
| | | |
| | | // show part page |
| | | if (!empty($_GET['_frame'])) { |
| | |
| | | |
| | | $browser = new rcube_browser; |
| | | |
| | | send_nocacheing_headers(); |
| | | |
| | | // send download headers |
| | | if ($_GET['_download']) { |
| | | header("Content-Type: application/octet-stream"); |