以下PHP腳本中是否存在注入安全風險?
<?php
$empfaenger_1 = "[email protected]";
$sender = "[email protected]";
$name = $_POST['name'];
$telefon = $_POST['phone'];
$betreff = "Test";
$text =
"Please contact me
Name: $name
Telefon: $telefon";
mail($empfaenger_1, $betreff, $text,"from:$sender");
$url = htmlspecialchars($_SERVER['HTTP_REFERER']);
echo "<center><br><br>Thank you<br><br>";
echo "<center><a href='$url'>Back</a>";
好吧,所以我應該用htmlspecialchars消毒我想? – Alex 2012-04-03 13:08:41
我會使用'strip_tags'而不是htmlspecialchars文本查看器有更多的樂趣。此外htmlspecialchars可能會打破你的sonderzeichen。 – PiTheNumber 2012-04-03 13:10:50