Changeset 2077

Show
Ignore:
Timestamp:
06/22/06 07:56:42 (4 years ago)
Author:
qldrob
Message:

Merged revisions 2076 via svnmerge from
https://svn.sourceforge.net/svnroot/amportal/freepbx/branches/2.1

........

r2076 | qldrob | 2006-06-23 00:53:23 +1000 (Fri, 23 Jun 2006) | 2 lines


Fix for potential security hole if a shell escape character was in CALLERID(name) or (number)

........

Files:

Legend:

Unmodified
Added
Removed
Modified
Copied
Moved
  • freepbx/trunk

    • Property svnmerge-integrated changed from /freepbx/branches/2.1:1-2055 to /freepbx/branches/2.1:1-2055,2076
  • freepbx/trunk/amp_conf/astetc/extensions.conf

    r2072 r2077  
    738738exten => out_fax,1,txfax(${TXFAX_NAME}|caller) 
    739739exten => out_fax,2,Hangup 
    740 exten => h,1,system(/var/lib/asterisk/bin/fax-process.pl --to ${EMAILADDR} --from ${FAX_RX_FROM} --subject "Fax from ${CALLERID(number)} ${CALLERID(name)}" --attachment ${CALLERID(number)}.pdf --type application/pdf --file ${FAXFILE}); 
     740exten => h,1,system(/var/lib/asterisk/bin/fax-process.pl --to ${EMAILADDR} --from ${FAX_RX_FROM} --subject "Fax from ${URIENCODE(${CALLERID(number)})} ${URIENCODE(${CALLERID(name)})}" --attachment ${URIENCODE(${CALLERID(number)})}.pdf --type application/pdf --file ${FAXFILE}); 
    741741exten => h,2,Hangup() 
    742742