douchen7366 2013-10-30 17:13
浏览 19

PHP邮件功能不发送[关闭]

I have a php script using the mail function I would just like to know if someone sees a problem with this script before I contact the sys admin as he will probably not answer for a while

$headers = 'MIME-Version: 1.0' . "
";
$headers.= 'Content-type: text/html; charset=iso-8859-1' . "
";
$rating=$_POST['Rate'];
$subject= "review from website";
$name=$_POST['lname'].", ".$_POST['name'];
$from = $_POST['email'];
$to ="email@gmail.com";
$messageTo="BBComputers";
$headers = "From: ".$from. "
";
$message = htmlspecialchars($_POST['comment']);
$about = $_POST['product'];
$date=date("n-j-y \a\\t g:ia
");
mail($to,$subject,$message,$headers);
  • 写回答

1条回答 默认 最新

  • doujiao1948 2013-10-30 17:15
    关注

    I see a whole bunch of problems:

    • Your to address is incorrect: lose the trailing ;

    • There is no input validation.

    • Potential for header injection ($_POST["email"])

    • There is a random htmlspecialchars in there (why?)

    • $rating, $messageTo, $nameand $about are defined but never used.

    评论

报告相同问题?

悬赏问题

  • ¥50 potsgresql15备份问题
  • ¥15 Mac系统vs code使用phpstudy如何配置debug来调试php
  • ¥15 目前主流的音乐软件,像网易云音乐,QQ音乐他们的前端和后台部分是用的什么技术实现的?求解!
  • ¥60 pb数据库修改与连接
  • ¥15 spss统计中二分类变量和有序变量的相关性分析可以用kendall相关分析吗?
  • ¥15 拟通过pc下指令到安卓系统,如果追求响应速度,尽可能无延迟,是不是用安卓模拟器会优于实体的安卓手机?如果是,可以快多少毫秒?
  • ¥20 神经网络Sequential name=sequential, built=False
  • ¥16 Qphython 用xlrd读取excel报错
  • ¥15 单片机学习顺序问题!!
  • ¥15 ikuai客户端多拨vpn,重启总是有个别重拨不上