[rt-users] Still a MIME/HTML issue with rt-mailgate?

Jesse Vincent jesse at bestpractical.com
Mon Jun 2 13:10:36 EDT 2003


HTML mail is avaialble via the "Download" link.
Displaying HTML is a security issue that would make RT vulnerable to
"Cross Site Scripting" attacks.


On Mon, Jun 02, 2003 at 10:37:18AM -0400, Derek Buttineau wrote:
> Read a few threads where it sounded like others were having similar 
> problems with the rt-mailgate in rt3-0-2, though I'm unclear if there's 
> been a resolution to it?
> 
> The issue I'm experiencing is that when I send a text message through 
> the mailgate, regardless of size it appears in the queue as intended.  
> However if I reformat the same message to use some HTML encoding the 
> message cuts off and truncates.
> 
> I've even tried going up to the 3.0.3 development version, but I 
> experience the same problems there as well.
> 
> Any suggestions or solutions would be greatly appreciated.
> 
> Thanks,
> 
> Derek
> 
> _______________________________________________
> rt-users mailing list
> rt-users at lists.fsck.com
> http://lists.fsck.com/mailman/listinfo/rt-users
> 
> Have you read the FAQ? The RT FAQ Manager lives at http://fsck.com/rtfm
> 

-- 
http://www.bestpractical.com/rt  -- Trouble Ticketing. Free.



More information about the rt-users mailing list