add some security to mail script

This commit is contained in:
David Miller 2016-02-09 13:33:08 -05:00
parent 7d7d64472a
commit a9222141c1

View File

@ -1,19 +1,19 @@
<?php <?php
// Check for empty fields // Check for empty fields
if(empty($_POST['name']) || if(empty($_POST['name']) ||
empty($_POST['email']) || empty($_POST['email']) ||
empty($_POST['phone']) || empty($_POST['phone']) ||
empty($_POST['message']) || empty($_POST['message']) ||
!filter_var($_POST['email'],FILTER_VALIDATE_EMAIL)) !filter_var($_POST['email'],FILTER_VALIDATE_EMAIL))
{ {
echo "No arguments Provided!"; echo "No arguments Provided!";
return false; return false;
} }
$name = $_POST['name']; $name = strip_tags(htmlspecialchars($_POST['name']));
$email_address = $_POST['email']; $email_address = strip_tags(htmlspecialchars($_POST['email']));
$phone = $_POST['phone']; $phone = strip_tags(htmlspecialchars($_POST['phone']));
$message = $_POST['message']; $message = strip_tags(htmlspecialchars($_POST['message']));
// Create the email and send the message // Create the email and send the message
$to = 'yourname@yourdomain.com'; // Add your email address inbetween the '' replacing yourname@yourdomain.com - This is where the form will send a message to. $to = 'yourname@yourdomain.com'; // Add your email address inbetween the '' replacing yourname@yourdomain.com - This is where the form will send a message to.