我想知道我所做的是否会停止在我的电子邮件表格中注入。
<?php
if(isset($_POST['submit'])){
$to = "ask@mywebsite.co.uk";
$from = filter_var($_POST['email'], FILTER_SANITIZE_EMAIL);
$first_name = $_POST['first_name'];
$last_name = $_POST['last_name'];
$subject = "Form submission";
$subject2 = "Copy of your form submission";
$message = $first_name . " " . $last_name . " wrote the following:" . "\n\n" . $_POST['message'];
$message2 = "Here is a copy of your message " . $first_name . "\n\n" . $_POST['message'];
$headers = "From:" . $from;
$headers2 = "From:" . $to;
mail($to,$subject,$message,$headers);
mail($from,$subject2,$message2,$headers2);
echo "Mail Sent. Thank you " . $first_name . ", we will contact you shortly.";
}
?>
答案 0 :(得分:3)
标题是唯一的注入点,您只有一个变量来处理 $ from ,而您使用filter_var
答案 1 :(得分:3)