<?xml version="1.0" encoding="utf-8"?>
<!--  RSS generated by Flaimo.com RSS Builder [2009-11-21 00:44:41]  --> <rss version="2.0" xmlns:im="http://purl.org/rss/1.0/item-images/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" >
<channel>
<docs>http://mantis.phplist.com/</docs>
<description>Mantis - ISSUES</description>
<link>http://mantis.phplist.com/</link>
<title>Mantis - ISSUES</title>
<image>
<title>Mantis - ISSUES</title>
<url>http://mantis.phplist.com/images/mantis_logo_button.gif</url>
<link>http://mantis.phplist.com/</link>
<description>Mantis - ISSUES</description>
</image>
<category>All Projects</category>
<ttl>10</ttl>
<sy:updatePeriod>hourly</sy:updatePeriod>
<sy:updateFrequency>1</sy:updateFrequency>
<sy:updateBase>2009-11-21T00:44:40+00:00</sy:updateBase>
<item>
<title>0015367: Command-line access control is insecure</title>
<link>http://mantis.phplist.com/view.php?id=15367</link>
<description>In index.php, the USER environment variable is checked against the global $commandline_users to determine the process owner's access to invocation of PHPList scripts from the command line.  This method is insecure as environment variables are easily spoofed. &lt;br /&gt;
&lt;br /&gt;
If you really want to implement this type of access control, you can check for the process user with posix_getpwuid(posix_getuid()).  However, these functions are only available through the POSIX extension which is not always loaded.&lt;br /&gt;
&lt;br /&gt;
This access control seems unnecessary anyway, as POSIX permissions and ACLs are sufficient.</description>
<guid>http://mantis.phplist.com/view.php?id=15367</guid>
<author>marxarelli &lt;marxarelli@example.com&gt;</author>
<comments>http://mantis.phplist.com/view.php?id=15367#bugnotes</comments>
</item>
<item>
<title>0015366: Add basic template ownership</title>
<link>http://mantis.phplist.com/view.php?id=15366</link>
<description>This patch adds template ownership to phplist.&lt;br /&gt;
It means that each admin can create their own templates and one admin cannot see another admin's template.&lt;br /&gt;
&lt;br /&gt;
I copy and paste in &quot;Additional information&quot; field the basic instructions on how to use it.&lt;br /&gt;
&lt;br /&gt;
I am very interested in this patch becoming part of the official phplist.&lt;br /&gt;
&lt;br /&gt;
So I am ready to correct it as many times as it is needed so that it fits the way that you want things to be coded or if it needs to be improved somehow or whatever.&lt;br /&gt;
&lt;br /&gt;
I think I have done a great job because I have also coded the database upgrade part but it's up to you to judge my work so that we can improve it a lot better and add it to official phplist upstream code.  &lt;br /&gt;
&lt;br /&gt;
Thank you very much for your attention.&lt;br /&gt;
&lt;br /&gt;
adrian15</description>
<guid>http://mantis.phplist.com/view.php?id=15366</guid>
<author>adrian15 &lt;adrian15@example.com&gt;</author>
<comments>http://mantis.phplist.com/view.php?id=15366#bugnotes</comments>
</item>
<item>
<title>0015283: v2.10.10: Date criteria does not work</title>
<link>http://mantis.phplist.com/view.php?id=15283</link>
<description>Using Date attributes as criteria does not seem to work anymore.&lt;br /&gt;
&lt;br /&gt;
This issue is reported by Aidan:&lt;br /&gt;
==== START QUOTE ====&lt;br /&gt;
On the Criteria tab, I try to add a criterion based on the date attribute - I choose the date attribute from the dropdown and enter the date in the format specified, dd-mm-yyyy, and click 'Add Criterion'. But it replaces the date I entered with 0. I get the message 'Adding Submission Date isbefore 0' and it adds a line to the 'Existing Criteria' table which also has '0' in the values column.&lt;br /&gt;
&lt;br /&gt;
Running the Calculate function shows that this criterion has no effect on the number of results returned.&lt;br /&gt;
=== END QUOTE ===&lt;br /&gt;
Source: &lt;a href=&quot;http://forums.phplist.com/viewtopic.php?f=17&amp;t=24512#p61910&quot;&gt;http://forums.phplist.com/viewtopic.php?f=17&amp;t=24512#p61910&lt;/a&gt; [&lt;a href=&quot;http://forums.phplist.com/viewtopic.php?f=17&amp;t=24512#p61910&quot; target=&quot;_blank&quot;&gt;^&lt;/a&gt;]&lt;br /&gt;
&lt;br /&gt;
Issue confirmed on my installation too.</description>
<guid>http://mantis.phplist.com/view.php?id=15283</guid>
<author>h2b2 &lt;h2b2@example.com&gt;</author>
<comments>http://mantis.phplist.com/view.php?id=15283#bugnotes</comments>
</item>
<item>
<title>0015359: User Specific Authentication Pages Loose Formatting</title>
<link>http://mantis.phplist.com/view.php?id=15359</link>
<description>when the phplis driven site directs a user to a user specific login page (one that needs a password) the formatting of the page becomes generic causing the user to think they have left the current site.  This is causing some users to think they have been redirected under false pretenses.  It happens when ever they are asked for their password.&lt;br /&gt;
&lt;br /&gt;
There is a complete list of what has been found and done to this point at the following link in the forums&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://forums.phplist.com/viewtopic.php?f=17&amp;t=28879&quot;&gt;http://forums.phplist.com/viewtopic.php?f=17&amp;t=28879&lt;/a&gt; [&lt;a href=&quot;http://forums.phplist.com/viewtopic.php?f=17&amp;t=28879&quot; target=&quot;_blank&quot;&gt;^&lt;/a&gt;]</description>
<guid>http://mantis.phplist.com/view.php?id=15359</guid>
<author>rrrrob &lt;rrrrob@example.com&gt;</author>
<comments>http://mantis.phplist.com/view.php?id=15359#bugnotes</comments>
</item>
<item>
<title>0015320: Unsubscription should only be possible by a subscriber himself and not by a third person</title>
<link>http://mantis.phplist.com/view.php?id=15320</link>
<description>It's possible to unsubscribe somebody else just with the knowledge of his email address (e.g. with mydomain.com/lists/?unsubscribe). One does not have to know his personal preference/unsubscribe link. The unsubscribed user is _immediately_ put on the blacklist which is probably not what he want's to. &lt;br /&gt;
&lt;br /&gt;
I think that this should not be possible. This is an inconsitent behaviour related to the procedure of suscribing where a confirmation mail is needed. Also, this is an security issue.&lt;br /&gt;
&lt;br /&gt;
Unsubscribing should only be possible using one's personal preference link which is normally included in every mailing or which can be sent to the user by mail upon request. If the unsubscribe process should be possible using the unsubscribe link as described above (without any userid), there should be sent a confirmation link to the user.&lt;br /&gt;
&lt;br /&gt;
This functionality should be provided without the need of enabling user passwords. &lt;br /&gt;
&lt;br /&gt;
Thorsten</description>
<guid>http://mantis.phplist.com/view.php?id=15320</guid>
<author>Thorsten Albrecht &lt;Thorsten Albrecht@example.com&gt;</author>
<comments>http://mantis.phplist.com/view.php?id=15320#bugnotes</comments>
</item>
<item>
<title>0015226: User updates preferrences and receives page error - Undefined Index &amp; Variable (v.2.10.9)</title>
<link>http://mantis.phplist.com/view.php?id=15226</link>
<description>Error page occurring when user follows link in received mail to update their details.  The correct userid is parsed and the user's details displayed ready for ammendment but when these have been changed and the update button clicked the error page appears as described in additional information.&lt;br /&gt;
&lt;br /&gt;
Observations:&lt;br /&gt;
User still receives the email notification of an update taking place with the new updated details.&lt;br /&gt;
&lt;br /&gt;
The email being referred to as an undefined index relates to the senders email not the users or the noreply one used for system messages.&lt;br /&gt;
&lt;br /&gt;
(Could not specify version in Product Version drop down as 2.10.9 not available for selection.)</description>
<guid>http://mantis.phplist.com/view.php?id=15226</guid>
<author>spiro &lt;spiro@example.com&gt;</author>
<comments>http://mantis.phplist.com/view.php?id=15226#bugnotes</comments>
</item>
<item>
<title>0015365: Wrong description of MAILQUEUE_BATCH_PERIOD in config file</title>
<link>http://mantis.phplist.com/view.php?id=15365</link>
<description>The description of MAILQUEUE_BATCH_PERIOD is wrong. &lt;br /&gt;
&lt;br /&gt;
It says: &quot;MAILQUEUE_BATCH_PERIOD define the length of one batch processing period, in seconds (3600 is an hour)&quot;&lt;br /&gt;
&lt;br /&gt;
This is not true. Instead, it defines the waiting time between two batches. &lt;br /&gt;
&lt;br /&gt;
E.g., I am using the following settings: &lt;br /&gt;
&lt;br /&gt;
define(&quot;MAILQUEUE_BATCH_SIZE&quot;,10);&lt;br /&gt;
define(&quot;MAILQUEUE_BATCH_PERIOD&quot;,1);&lt;br /&gt;
&lt;br /&gt;
What happens is that I am sending 10 mails per batch and the web interface waits for 1 second before reloading and sending the next 100 mails.&lt;br /&gt;
&lt;br /&gt;
Thorsten</description>
<guid>http://mantis.phplist.com/view.php?id=15365</guid>
<author>Thorsten Albrecht &lt;Thorsten Albrecht@example.com&gt;</author>
<comments>http://mantis.phplist.com/view.php?id=15365#bugnotes</comments>
</item>
<item>
<title>0015363: addAbsoluteResources does not / or fails in matching schema</title>
<link>http://mantis.phplist.com/view.php?id=15363</link>
<description>function: addAbsoluteResources (lib.php line 533)&lt;br /&gt;
&lt;br /&gt;
the preg_match cannot match because &quot;[x|y|z]&quot; is used instead of &quot;(x|y|z)&quot;&lt;br /&gt;
AND&lt;br /&gt;
after this it matched (a failure) on links to if &quot;http&quot; are in the link anywhere.&lt;br /&gt;
&lt;br /&gt;
Imagine link:&lt;br /&gt;
   a href=&quot;/.bin/fwd.fcgi?&lt;a href=&quot;http://www.b2b-deutschland.de/wirtschaftsnews/091110/duerftige-aussichten-fuer-arcandor-glaeubiger/index.php&quot;&quot;&gt;http://www.b2b-deutschland.de/wirtschaftsnews/091110/duerftige-aussichten-fuer-arcandor-glaeubiger/index.php&quot;&lt;/a&gt; [&lt;a href=&quot;http://www.b2b-deutschland.de/wirtschaftsnews/091110/duerftige-aussichten-fuer-arcandor-glaeubiger/index.php&quot;&quot; target=&quot;_blank&quot;&gt;^&lt;/a&gt;]&lt;br /&gt;
It matched, but should not.&lt;br /&gt;
&lt;br /&gt;
Result the url was not absolutized.&lt;br /&gt;
&lt;br /&gt;
Attended result for website=www.b2b-deutschland.de should be:&lt;br /&gt;
  a href=&quot;&lt;a href=&quot;http://www.b2b-deutschland.de/.bin/fwd.fcgi?http://www.b2b-deutschland.de/wirtschaftsnews/091110/duerftige-aussichten-fuer-arcandor-glaeubiger/index.php&quot;&quot;&gt;http://www.b2b-deutschland.de/.bin/fwd.fcgi?http://www.b2b-deutschland.de/wirtschaftsnews/091110/duerftige-aussichten-fuer-arcandor-glaeubiger/index.php&quot;&lt;/a&gt; [&lt;a href=&quot;http://www.b2b-deutschland.de/.bin/fwd.fcgi?http://www.b2b-deutschland.de/wirtschaftsnews/091110/duerftige-aussichten-fuer-arcandor-glaeubiger/index.php&quot;&quot; target=&quot;_blank&quot;&gt;^&lt;/a&gt;]&lt;br /&gt;
&lt;br /&gt;
Patch:</description>
<guid>http://mantis.phplist.com/view.php?id=15363</guid>
<author>neffets &lt;neffets@example.com&gt;</author>
<comments>http://mantis.phplist.com/view.php?id=15363#bugnotes</comments>
</item>
<item>
<title>0015364: minor issue with click tracking and anti-phishing software</title>
<link>http://mantis.phplist.com/view.php?id=15364</link>
<description>many versions of anti-phishing , either plugins, or built into mail clients, or via anti-spam systems will see non-matching url's when the a href (the local, trackable url, the domain) doesn't match the one that you are actually directed to.&lt;br /&gt;
&lt;br /&gt;
I would not having the 'visible' url be the same as the real url.&lt;br /&gt;
&lt;br /&gt;
Without something, it makes phplist emails with click tracing on seem like spam or phishing emails.&lt;br /&gt;
&lt;br /&gt;
worse yet, would be if the target url (original one) was https.&lt;br /&gt;
&lt;br /&gt;
(reason I know alot about this, is we produce anti-spam products that include anti-phishing functions)</description>
<guid>http://mantis.phplist.com/view.php?id=15364</guid>
<author>scheidell &lt;scheidell@example.com&gt;</author>
<comments>http://mantis.phplist.com/view.php?id=15364#bugnotes</comments>
</item>
<item>
<title>0015362: overall handling of charsets</title>
<link>http://mantis.phplist.com/view.php?id=15362</link>
<description>You can enter bits of text at several locations, ranging from config file (plain text email user name) to configuration (database). At no point (it seems) the charset of user input is been checked or converted to UTF-8. You might end up with a mixture of Charsets, depending on the browser settings of the PHPList users.&lt;br /&gt;
Additionally PHPList does not send an content-type HTTP header containing charset information, which will produce bad output depending on the users browser settings. You really should send something like &quot;content-type: text/plain; charset=utf-8&quot;.</description>
<guid>http://mantis.phplist.com/view.php?id=15362</guid>
<author>EdgarWahn &lt;EdgarWahn@example.com&gt;</author>
<comments>http://mantis.phplist.com/view.php?id=15362#bugnotes</comments>
</item>
<item>
<title>0015361: Attribut value is not saved</title>
<link>http://mantis.phplist.com/view.php?id=15361</link>
<description>Havingh set an own table prefix the value of an attribute of the type select is not saved on subscription.&lt;br /&gt;
&lt;br /&gt;
The bug ist in &quot;admin/commonlib/lib/userlib.php&quot; from line 913 on.&lt;br /&gt;
&lt;br /&gt;
WRONG:&lt;br /&gt;
      $curval = Sql_Fetch_Row_Query(sprintf('select id from phplist_listattr_%s&lt;br /&gt;
      where name = &quot;%s&quot;',$atttable,$data[&quot;displayvalue&quot;]),1);&lt;br /&gt;
      if (!$curval[0] &amp;&amp; $data['displayvalue'] &amp;&amp; $data['displayvalue'] != '') {&lt;br /&gt;
        Sql_Query(sprintf('insert into phplist_listattr_%s (name) values(&quot;%s&quot;)',$atttable,&lt;br /&gt;
        $data[&quot;displayvalue&quot;]));&lt;br /&gt;
&lt;br /&gt;
RIGHT:&lt;br /&gt;
&lt;br /&gt;
      $curval = Sql_Fetch_Row_Query(sprintf('select id from ' . $usertable_prefix . 'listattr_%s&lt;br /&gt;
        where name = &quot;%s&quot;',$atttable,$data[&quot;displayvalue&quot;]),1);&lt;br /&gt;
      if (!$curval[0] &amp;&amp; $data['displayvalue'] &amp;&amp; $data['displayvalue'] != '') {&lt;br /&gt;
        Sql_Query(sprintf('insert into ' . $usertable_prefix . 'listattr_%s (name) values(&quot;%s&quot;)',$atttable,&lt;br /&gt;
          $data[&quot;displayvalue&quot;]));</description>
<guid>http://mantis.phplist.com/view.php?id=15361</guid>
<author>Subhash &lt;Subhash@example.com&gt;</author>
<comments>http://mantis.phplist.com/view.php?id=15361#bugnotes</comments>
</item>
<item>
<title>0015309: get blacklisted and see the html output when tring to subscribe</title>
<link>http://mantis.phplist.com/view.php?id=15309</link>
<description>crash because its visible and customer in bad mood!&lt;br /&gt;
&lt;br /&gt;
get blacklisted and see the html output when trying to subscribe to a list: dublicate html output. :-( &lt;br /&gt;
v2.10.10</description>
<guid>http://mantis.phplist.com/view.php?id=15309</guid>
<author>flobee &lt;flobee@example.com&gt;</author>
<comments>http://mantis.phplist.com/view.php?id=15309#bugnotes</comments>
</item>
<item>
<title>0015357: Develope Swift mailer pluggin that would allow phplist message sending to increase exponentionaly!</title>
<link>http://mantis.phplist.com/view.php?id=15357</link>
<description>Wants to find out where we are with possibly creating a swift mailer pluggin to be added to the defaiult phplist plugin. I have a dedicated server I can donate to development. &lt;br /&gt;
&lt;br /&gt;
Swift mailer would allow load balancing between servers with phpmailer doesn't support. Load balancing would safely and effienctly increase phplist performance beyond 30,000 messages per hour. It may make things easier for those using shared hosting as well&lt;br /&gt;
&lt;br /&gt;
Some of Swift Mailer Features:&lt;br /&gt;
&lt;br /&gt;
* Send uses one single connection to the SMTP server or MTA&lt;br /&gt;
* Doesn't rely on mail()&lt;br /&gt;
* Custom Headers&lt;br /&gt;
* Multiple encoding options&lt;br /&gt;
* Unlimited redundant connections (can use mixed types too)&lt;br /&gt;
* Connection rotating/load balancing&lt;br /&gt;
* TLS Support - for Gmail servers&lt;br /&gt;
* Embedded Images or other file types&lt;br /&gt;
* Builds and sends Multipart messages&lt;br /&gt;
* Sends single-part emails as usual&lt;br /&gt;
* Fast Cc and Bcc handling&lt;br /&gt;
* Unicode UTF-8 support, with auto-detection&lt;br /&gt;
* Handles denied recipients in batch mailing whilst still delivering to the others&lt;br /&gt;
* Optional auto-detection of SMTP or Sendmail settings&lt;br /&gt;
* Batch emailing with multiple To's or without&lt;br /&gt;
* Send to hundreds of thousands of addresses without cron&lt;br /&gt;
* Support for multiple attachments&lt;br /&gt;
* Protection against header injection&lt;br /&gt;
* Set message priority&lt;br /&gt;
* Request Read Receipts&lt;br /&gt;
* Sendmail (or other binary) support&lt;br /&gt;
* Pluggable SMTP Authentication (LOGIN, PLAIN, MD5-CRAM, POP Before SMTP)&lt;br /&gt;
* Anti-Flooding support (reconnect every X emails) via plugin&lt;br /&gt;
* Secure Socket Layer connections (SSL)&lt;br /&gt;
* Loadable plugin support with event handling features</description>
<guid>http://mantis.phplist.com/view.php?id=15357</guid>
<author>mike mckoy &lt;mike mckoy@example.com&gt;</author>
<comments>http://mantis.phplist.com/view.php?id=15357#bugnotes</comments>
</item>
<item>
<title>0015360: Click Tracking is not working for links in the body of the message, only for those in the footer.</title>
<link>http://mantis.phplist.com/view.php?id=15360</link>
<description>Hi,&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Click Tracking is not working for links in the body of the message, only for those in the footer i.e., for unsubsribe and Forward links.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Any help would be appreciated.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Thanks,&lt;br /&gt;
Ramya</description>
<guid>http://mantis.phplist.com/view.php?id=15360</guid>
<author>ramya123 &lt;ramya123@example.com&gt;</author>
<comments>http://mantis.phplist.com/view.php?id=15360#bugnotes</comments>
</item>
<item>
<title>0015345: &quot;phplist powered by phplist&quot; in the admin pages. No version in the user pages.</title>
<link>http://mantis.phplist.com/view.php?id=15345</link>
<description>The user pages display nothing after the word &quot;version&quot;. If it's on purpose, the word &quot;version&quot; should be removed and the version number should be removed from the admin log-in page.&lt;br /&gt;
&lt;br /&gt;
The admin pages display &quot;phplist powered by phplist&quot;.</description>
<guid>http://mantis.phplist.com/view.php?id=15345</guid>
<author>lwc &lt;lwc@example.com&gt;</author>
<comments>http://mantis.phplist.com/view.php?id=15345#bugnotes</comments>
</item>
<item>
<title>0015325: SMTP code is partially broken (revisited)</title>
<link>http://mantis.phplist.com/view.php?id=15325</link>
<description>cipixul reports that the code changes applied to &quot;admin/class.phplistmailer.php&quot; in order to fix issue 8590 can result in trouble:&lt;br /&gt;
&lt;br /&gt;
===== Start Quote =====&lt;br /&gt;
&lt;br /&gt;
The code is wrong because it uses PHPMAILERHOST only if the admin set phpmailer_user, which is not always the case, and as we run several smtpd servers on same machine, we don't authenticate to our smtpd instances because they're local.&lt;br /&gt;
&lt;br /&gt;
===== End Quote =====&lt;br /&gt;
Source: &lt;a href=&quot;http://forums.phplist.com/viewtopic.php?f=17&amp;t=23830#p67628&quot;&gt;http://forums.phplist.com/viewtopic.php?f=17&amp;t=23830#p67628&lt;/a&gt; [&lt;a href=&quot;http://forums.phplist.com/viewtopic.php?f=17&amp;t=23830#p67628&quot; target=&quot;_blank&quot;&gt;^&lt;/a&gt;]</description>
<guid>http://mantis.phplist.com/view.php?id=15325</guid>
<author>h2b2 &lt;h2b2@example.com&gt;</author>
<comments>http://mantis.phplist.com/view.php?id=15325#bugnotes</comments>
</item>
<item>
<title>0015291: SMTP send won't work without authentication</title>
<link>http://mantis.phplist.com/view.php?id=15291</link>
<description>Logic in constructor of class PHPlistMailer is wrong in the case of using SMTP.&lt;br /&gt;
&lt;br /&gt;
The offending code is: &lt;br /&gt;
&lt;br /&gt;
if (defined('PHPMAILERHOST') &amp;&amp; PHPMAILERHOST != '') &amp;&amp; isset($GLOBALS['phpmailer_smtpuser']) &amp;&amp; $GLOBALS['phpmailer_smtpuser'] != '') {&lt;br /&gt;
....&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
SMTP will only be set if phpmailer_smtpuser has been set in the configuration. This precludes the use of SMTP servers which do not require authentication.&lt;br /&gt;
&lt;br /&gt;
The fix is simple and is left as an exercise for the maintainers.</description>
<guid>http://mantis.phplist.com/view.php?id=15291</guid>
<author>openside &lt;openside@example.com&gt;</author>
<comments>http://mantis.phplist.com/view.php?id=15291#bugnotes</comments>
</item>
<item>
<title>0000740: PHPList Archive</title>
<link>http://mantis.phplist.com/view.php?id=740</link>
<description>Guys, &lt;br /&gt;
&lt;br /&gt;
I've been using Mojo Mailing List since January and its been very good. I really like PHPList a lot but one thing it do not have is automatically archive on website. &lt;br /&gt;
&lt;br /&gt;
Wonder if they ever will upgrade PHPList with it in near future? &lt;br /&gt;
&lt;br /&gt;
Smile, &lt;br /&gt;
gwlj</description>
<guid>http://mantis.phplist.com/view.php?id=740</guid>
<author>grantlairdjr &lt;grantlairdjr@example.com&gt;</author>
<comments>http://mantis.phplist.com/view.php?id=740#bugnotes</comments>
</item>
<item>
<title>0015358: Import does not strip doublequote text delimiters when using 'import emails with the same values for attributes'</title>
<link>http://mantis.phplist.com/view.php?id=15358</link>
<description>By default Openoffice Calc uses the text delimter &quot; when exporting CSV files. When importing to phplist it appears not to remove these which results in email addresses that look like: &quot;&lt;a href=&quot;mailto:name@domain.com&quot;&gt;name@domain.com&lt;/a&gt;&quot; instead of just: &lt;a href=&quot;mailto:name@domain.com&quot;&gt;name@domain.com&lt;/a&gt;. The actual import itself goes fine but then later these doublequotes result in the addresses being regarded as invalid by phplist.&lt;br /&gt;
&lt;br /&gt;
Line 407 of importcsv.php includes the code: &lt;br /&gt;
&lt;br /&gt;
$line = str_replace('&quot;', '', $line);&lt;br /&gt;
&lt;br /&gt;
For whatever reason - i am not a competent enough coder to work out what's happening here - the code above either doesn't get called or does not have the intended effect.&lt;br /&gt;
&lt;br /&gt;
As OpenOffice is a popular choice both for regular users and for those looking to convert xls files and export them as csv, i contend that this should just work without having to manually alter the text delimiter.&lt;br /&gt;
&lt;br /&gt;
I have twice seen this effect. First when importing a large number of email addresses and then secondly through exporting a CSV file consisting of just two email addresses in an attempt to replicate the behaviour.&lt;br /&gt;
&lt;br /&gt;
This appears consistent arcoss both 2.10.9 and 2.10.10.</description>
<guid>http://mantis.phplist.com/view.php?id=15358</guid>
<author>crowdofone &lt;crowdofone@example.com&gt;</author>
<comments>http://mantis.phplist.com/view.php?id=15358#bugnotes</comments>
</item>
<item>
<title>0015341: security - forgotpassword value not checked/eval'd</title>
<link>http://mantis.phplist.com/view.php?id=15341</link>
<description>/lists/admin when entering value to send an email for 'forgot password', the value is not checked.&lt;br /&gt;
&lt;br /&gt;
Fix included in additional info.</description>
<guid>http://mantis.phplist.com/view.php?id=15341</guid>
<author>dhartford &lt;dhartford@example.com&gt;</author>
<comments>http://mantis.phplist.com/view.php?id=15341#bugnotes</comments>
</item>
<item>
<title>0015349: Need stripslashes when displaying and/or searcing for user attributes</title>
<link>http://mantis.phplist.com/view.php?id=15349</link>
<description>Just like &lt;a href=&quot;http://mantis.phplist.com/view.php?id=1152&quot;&gt;http://mantis.phplist.com/view.php?id=1152&lt;/a&gt; [&lt;a href=&quot;http://mantis.phplist.com/view.php?id=1152&quot; target=&quot;_blank&quot;&gt;^&lt;/a&gt;] only for user attributes. &lt;br /&gt;
&lt;br /&gt;
This is relevant for:&lt;br /&gt;
1) The usage of [attribute] in messages.&lt;br /&gt;
2) Searching by attribute in the list of users.&lt;br /&gt;
3) Displaying the search result of searching by attribute in the list of users&lt;br /&gt;
4) The user's preferences page&lt;br /&gt;
5) The admin's edit screen of individual users.&lt;br /&gt;
&lt;br /&gt;
Things like such users are being unsearchable (by the relevant attribute) - even if you use slash in your search - is why I classified it as a major error.</description>
<guid>http://mantis.phplist.com/view.php?id=15349</guid>
<author>lwc &lt;lwc@example.com&gt;</author>
<comments>http://mantis.phplist.com/view.php?id=15349#bugnotes</comments>
</item>
<item>
<title>0015188: PHP Error</title>
<link>http://mantis.phplist.com/view.php?id=15188</link>
<description>On the bottom of lists/admin/ along with several other admin pages I get this error message:&lt;br /&gt;
&lt;br /&gt;
Notice: ob_end_flush() [ref.outcontrol]: failed to delete and flush buffer. No buffer to delete or flush. in /nfs/c02/h03/mnt/27557/domains/puyallup-tribe.com/html/mail/lists/admin/index.php on line 409&lt;br /&gt;
phplist version 2.10.7</description>
<guid>http://mantis.phplist.com/view.php?id=15188</guid>
<author>anthropos9 &lt;anthropos9@example.com&gt;</author>
<comments>http://mantis.phplist.com/view.php?id=15188#bugnotes</comments>
</item>
<item>
<title>0015300: Resubscribing previous user (i.e. blacklisted)</title>
<link>http://mantis.phplist.com/view.php?id=15300</link>
<description>There are two possibilities with this depending on whether users are required to use a password.&lt;br /&gt;
&lt;br /&gt;
config.php define(&quot;ASKFORPASSWORD&quot;,0);&lt;br /&gt;
&lt;br /&gt;
With the above setting in config it still only works if a fix that I found in the forum is applied to the admin/subscribelib2.php around line 365 under &quot;if ($blacklisted) {&quot; rem out &quot;return 1&quot;.  This then allows the new subscription to send out the request for confirmation email and once the url in that is clicked the user is removed from being blacklisted.&lt;br /&gt;
&lt;br /&gt;
With the ASKFORPASSWORD set to 1, when someone tries to resubscribe the subscription page asks for a password to be created and then reconfirmed as with any user trying to subscribe with the password option switched on.  However, instead of the system updating the password with the new one from this registration as it does with the rest of the user details being resubscribed, it reloads the subscribe page stating that the email already exists with a different password, breaking the resubscription process unless the user knows or requests their old password.  It would be cleaner if whatever password they chose upon attempting to resubscribe was taken as their new data as it does with other attributes from the subscribe page.</description>
<guid>http://mantis.phplist.com/view.php?id=15300</guid>
<author>spiro &lt;spiro@example.com&gt;</author>
<comments>http://mantis.phplist.com/view.php?id=15300#bugnotes</comments>
</item>
<item>
<title>0015350: &quot;Send Message&quot; screen is incomplete</title>
<link>http://mantis.phplist.com/view.php?id=15350</link>
<description>I am using IE 8, and am experiencing the same problem that was reported in issue # 004030.  I can see the full screen in your demo, but not in the version I have installed.  It was installed using Fantastico and I haven't changed any default config settings.</description>
<guid>http://mantis.phplist.com/view.php?id=15350</guid>
<author>LouiseB &lt;LouiseB@example.com&gt;</author>
<comments>http://mantis.phplist.com/view.php?id=15350#bugnotes</comments>
</item>
<item>
<title>0015351: Bug in MySql installation script of PHPList</title>
<link>http://mantis.phplist.com/view.php?id=15351</link>
<description>After installing PHPList on server and going through the admin panel I noticed that I was receiving errors such as table does not exist. This was very strange so I decided to do some further investigation.&lt;br /&gt;
&lt;br /&gt;
Findings:&lt;br /&gt;
&lt;br /&gt;
On line number 1087 in the phplist.sql:&lt;br /&gt;
&lt;br /&gt;
INSERT INTO `phplist_user_blacklist_data` VALUES ('&lt;a href=&quot;mailto:billgates@microsoft.com&quot;&gt;billgates@microsoft.com&lt;/a&gt;','reason','I\\\'m not really that interested in your newsletter anymore. Sorry.');&lt;br /&gt;
&lt;br /&gt;
This is not correct as the \\\ in the query escapes the rest of the sql and the remaining tables are not executed this results in a broken installation.&lt;br /&gt;
&lt;br /&gt;
The correct sql is:&lt;br /&gt;
INSERT INTO `phplist_user_blacklist_data` VALUES ('&lt;a href=&quot;mailto:billgates@microsoft.com&quot;&gt;billgates@microsoft.com&lt;/a&gt;','reason','I\'m not really that interested in your newsletter anymore. Sorry.');&lt;br /&gt;
&lt;br /&gt;
After doing this fix and adding the tables below this line number everything worked perfectly.</description>
<guid>http://mantis.phplist.com/view.php?id=15351</guid>
<author>shez001 &lt;shez001@example.com&gt;</author>
<comments>http://mantis.phplist.com/view.php?id=15351#bugnotes</comments>
</item>
</channel>
</rss>
