I have tested the *upstream* 0.8.14-rc3, and it fixes almost all issues mentioned in this bug report.
If you select "Show HTML messages" under Options and then view the message ilohamail1.msg, there will still be an XSS bug. // Ulf Harnhammar -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]