Answer the question
In order to leave comments, you need to log in
Can a site be hacked through a form to send messages?
Good afternoon, can the site be hacked
through the form of sending messages, the form is not connected with the database, it only works with the mail() function etc.
The simple form accepts "name" and "phone".
Thank you!
Answer the question
In order to leave comments, you need to log in
Unfiltered input - this means potential css, this means they can receive cookies, incl. administrator, if you slip him a link with this css (he must follow it, but usually it's not difficult, social engineering works very well), and then, having an administrator password, you can usually do much more, and without hacking.
p.s. check what happens if the form data is sent as a GET request instead of a POST.
If the data is not validated, then it can. Once, a long time ago, there is no longer an archive, we had it - there was a page with a demo of the product, hung and hung
... fatal but annoying.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question