表格验证评估

时间:2014-09-30 15:54:01

标签: php forms validation

请告知以下表单验证脚本是否足够安全,以避免大多数类型(所有类型?)的联系表单漏洞利用?我已经在网上找到了这个脚本,添加了一些额外的php结果,希望能让它更安全,但不能完全确定它是否适用于此目的。

    if ($_SERVER["REQUEST_METHOD"] == "POST" && !empty($_SERVER['HTTP_X_REQUESTED_WITH']) && strtolower($_SERVER['HTTP_X_REQUESTED_WITH']) == 'xmlhttprequest') {
    // Get the form fields and remove whitespace.
    $name = strip_tags(trim($_POST["name"]));
    $name = str_replace(array("\r","\n"),array(" "," "),$name);
    $email = filter_var(trim($_POST["email"]), FILTER_SANITIZE_EMAIL);
    $message = trim($_POST["message"]);

    // Check that data was sent to the mailer.
    if ( empty($name) OR empty($message) OR !filter_var($email, FILTER_VALIDATE_EMAIL)) {
        // Set a 400 (bad request) response code and exit.
        //http_response_code(400);
        echo "Oops! There was a problem with your submission. Please complete the form and try again.";
        exit;
    }

    // Set the recipient email address.
    // FIXME: Update this to your desired email address.
    $recipient = "email_here";

    // Set the email subject.
    $subject = "New contact from $name";

    // Build the email content.
    $email_content = "Name: $name\n";
    $email_content .= "Email: $email\n\n";
    $email_content .= "Message:\n$message\n";

    // Build the email headers.

    $email_headers = "MIME-Version: 1.0\r\n";
    $email_headers .= "Content-type: text/html; charset=utf-8\r\n"; 
    $email_headers .= "From: $name <$email>\r\n";
    $email_headers .= "Reply-To: $email\r\n";
    $email_headers .= "Return-Path: $email\r\n";
    $email_headers .= "Organization: Bilingual Counselling\r\n"; 

    // Send the email.
    if (mail($recipient, $subject, $email_content, $email_headers)) {
        // Set a 200 (okay) response code.
        //http_response_code(200);
        echo "Thank You! Your message has been sent.";
    } else {
        // Set a 500 (internal server error) response code.
        //http_response_code(500);
        echo "Oops! Something went wrong and we couldn't send your message.";
    }

}

1 个答案:

答案 0 :(得分:1)

不安全。例如,您不能对$message执行任何操作 - 您应该在此使用strip_tags()功能。现在,您将此变量直接包含在电子邮件内容中。