Posted by Michael Fesser on 11/24/06 01:23
..oO(moosus)
>I do understand about code injection.
>
>I guess the question was more "is it possible to inject onto 'string
>message' parameter of the email function?
No. Injection requires a modification of header fields. In case of the
mail() function you have to take care of the 1st, 2nd and 4th parameter.
Micha
[Back to original message]
|