|
|
@ -830,6 +830,9 @@ function rcmail_mod_css_styles($source, $container_id)
|
|
|
|
if (preg_match('/expression|behavior|url\(|import/', $stripped))
|
|
|
|
if (preg_match('/expression|behavior|url\(|import/', $stripped))
|
|
|
|
return '/* evil! */';
|
|
|
|
return '/* evil! */';
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
// remove css comments (sometimes used for some ugly hacks)
|
|
|
|
|
|
|
|
$source = preg_replace('!/\*(.+)\*/!Ums', '', $source);
|
|
|
|
|
|
|
|
|
|
|
|
// cut out all contents between { and }
|
|
|
|
// cut out all contents between { and }
|
|
|
|
while (($pos = strpos($source, '{', $last_pos)) && ($pos2 = strpos($source, '}', $pos)))
|
|
|
|
while (($pos = strpos($source, '{', $last_pos)) && ($pos2 = strpos($source, '}', $pos)))
|
|
|
|
{
|
|
|
|
{
|
|
|
|