gtbikerider
Technical User
I'm getting email injection attacks on a CF server. (for background see
I want to abort the form processing if there's no form.email variable - or if it contains carraige returns. Does this code look right?
<cfif NOT isdefined ("form.emailaddress") OR find(chr(10),form.emailaddress) OR find(chr(13),form.emailaddress)>
<cfabort>
</cfif>
--
John
I want to abort the form processing if there's no form.email variable - or if it contains carraige returns. Does this code look right?
<cfif NOT isdefined ("form.emailaddress") OR find(chr(10),form.emailaddress) OR find(chr(13),form.emailaddress)>
<cfabort>
</cfif>
--
John