Thank you for this information.
I am just at the stage of working out the ways to untaint my data of which there may be many. I got that there shouldn't be any mail headers allowed and banned ':' from any field except the message body, plus HTML escaping any data input including that in the message body.
I now plan to include exclusion of newline characters in all but the message body as well.
My problem now resolves to how to untaint the message body but I will look at the nms code to pick up further clues and improvements
In reply to Re^2: FB, CGI and the nms offerings
by LesleyB
in thread FB, CGI and the nms offerings
by LesleyB
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |