You are here: Re: Register Globals « PHP « IT news, forums, messages
Re: Register Globals

Posted by Curt Zirzow on 11/04/05 22:52

On Thu, 03 Nov 2005 21:17:39 -0500, John Taylor-Johnston wrote:

> Ok, you are all used to working with register_gloabsl=off.
>
> mail($to, stripslashes($subject), wordwrap($message, 60), "From:
> $from\r\n");
>
> I change this line to:
>
> mail($to, stripslashes($_POST["subject"]), wordwrap($_POST["message"],
> 60), "From: $_POST["from"]\r\n");

You do realize you have an open relay. I can send in the post data:

&subject=I%20Love%20Your&from=something\r\nBCC:moreaddresses&message=a_mime_encoded_virus

Dont trust tainted variables, you should really fix that.


Curt.
--
http://news.zirzow.dyndns.org/

 

Navigation:

[Reply to this message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация