Using the bad_url in the INI seemed to keep McAfee from flagging the issue. So I'm considering it resolved. Thanks for all your help!
Welcome to the Tectite Forums! You can download and get support for our free PHP FormMail (form processor) and other free software.
Type: Posts; User: good1
Using the bad_url in the INI seemed to keep McAfee from flagging the issue. So I'm considering it resolved. Thanks for all your help!
Apparently changing to POST did not fix the issue. The problem is that any URL can be substituted in the bad_url field, the script does not verify what that URL should be. Doing so allows phishing...
Hello, I was just wondering if there has been any update to this?
Thanks!
Excellent! Thank you!
I use McAfee Secure on my website, it's recently found an exploit with my form. Apparently any value can be placed/subsituted in the bad_url hidden field in my form and the form then can be made...