【发布时间】:2016-01-12 00:02:56
【问题描述】:
我想知道我所做的是否会阻止我的电子邮件表单上的注入。
<?php
if(isset($_POST['submit'])){
$to = "ask@mywebsite.co.uk";
$from = filter_var($_POST['email'], FILTER_SANITIZE_EMAIL);
$first_name = $_POST['first_name'];
$last_name = $_POST['last_name'];
$subject = "Form submission";
$subject2 = "Copy of your form submission";
$message = $first_name . " " . $last_name . " wrote the following:" . "\n\n" . $_POST['message'];
$message2 = "Here is a copy of your message " . $first_name . "\n\n" . $_POST['message'];
$headers = "From:" . $from;
$headers2 = "From:" . $to;
mail($to,$subject,$message,$headers);
mail($from,$subject2,$message2,$headers2);
echo "Mail Sent. Thank you " . $first_name . ", we will contact you shortly.";
}
?>
【问题讨论】:
-
谢谢,我觉得这似乎太容易了。
-
这取决于你对“注入”的定义