Richard Lynch wrote:

> <?php
>   if (isset($_REQUEST['email'])){
>     $success = mail($_REQUEST['action'], 'un/subscribe',
> 'un/subscribe', "From: $_REQUEST[email]\r\nReply-to:
> $_REQUEST[email]");
>     if ($success) echo "Status Change Sent";
>     else echo "Unable to send Status Change";
>   }
> ?>

What if someone submitted:

action = [EMAIL PROTECTED]

email = [EMAIL PROTECTED] long winded evil spam message here

?

-- 
David Dorward       <http://blog.dorward.me.uk/>   <http://dorward.me.uk/>
                     Home is where the ~/.bashrc is

-- 
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php

Reply via email to