2014-09-30 50 views
0

请告知下面的表单验证脚本是否足够安全以避免大多数类型(所有类型)的联系表单漏洞利用?我发现这个脚本在线,添加了一些额外的PHP finctions,希望能够使它更安全,但并不能完全确定它是否适合这个目的。表单验证评估

if ($_SERVER["REQUEST_METHOD"] == "POST" && !empty($_SERVER['HTTP_X_REQUESTED_WITH']) && strtolower($_SERVER['HTTP_X_REQUESTED_WITH']) == 'xmlhttprequest') { 
    // Get the form fields and remove whitespace. 
    $name = strip_tags(trim($_POST["name"])); 
    $name = str_replace(array("\r","\n"),array(" "," "),$name); 
    $email = filter_var(trim($_POST["email"]), FILTER_SANITIZE_EMAIL); 
    $message = trim($_POST["message"]); 

    // Check that data was sent to the mailer. 
    if (empty($name) OR empty($message) OR !filter_var($email, FILTER_VALIDATE_EMAIL)) { 
     // Set a 400 (bad request) response code and exit. 
     //http_response_code(400); 
     echo "Oops! There was a problem with your submission. Please complete the form and try again."; 
     exit; 
    } 

    // Set the recipient email address. 
    // FIXME: Update this to your desired email address. 
    $recipient = "email_here"; 

    // Set the email subject. 
    $subject = "New contact from $name"; 

    // Build the email content. 
    $email_content = "Name: $name\n"; 
    $email_content .= "Email: $email\n\n"; 
    $email_content .= "Message:\n$message\n"; 

    // Build the email headers. 

    $email_headers = "MIME-Version: 1.0\r\n"; 
    $email_headers .= "Content-type: text/html; charset=utf-8\r\n"; 
    $email_headers .= "From: $name <$email>\r\n"; 
    $email_headers .= "Reply-To: $email\r\n"; 
    $email_headers .= "Return-Path: $email\r\n"; 
    $email_headers .= "Organization: Bilingual Counselling\r\n"; 

    // Send the email. 
    if (mail($recipient, $subject, $email_content, $email_headers)) { 
     // Set a 200 (okay) response code. 
     //http_response_code(200); 
     echo "Thank You! Your message has been sent."; 
    } else { 
     // Set a 500 (internal server error) response code. 
     //http_response_code(500); 
     echo "Oops! Something went wrong and we couldn't send your message."; 
    } 

} 
+0

不确定你在问什么。你的脚本是否工作或失败 - 如果是的话,错误是什么?还是你要求进行代码审查? – 2014-09-30 16:01:44

+0

你应该尝试一些xss反对它...我们不应该为你做这件事.. – Pogrindis 2014-09-30 16:02:42

+0

我不是要求代码给我,我要求代码回复和建议 – 2014-09-30 16:05:57

回答

1

这是不安全的。例如,你不用$message做任何事情 - 你应该在这里使用strip_tags()函数。现在你把这个变量持有的东西直接放入电子邮件内容中。

+0

谢谢,编辑。还有更多担忧吗? – 2014-09-30 16:18:07