| This article may not meet the general notability guideline. Please help to establish notability by adding reliable, secondary sources about the topic. If notability cannot be established, the article is likely to be merged or deleted. (July 2009) |
E-mail injection is a security vulnerability that can occur in Internet applications that are used to send e-mail messages. It is the email equivalent of HTTP Header Injection. Like SQL injection attacks, this vulnerability is one of a general class of vulnerabilities that occur when one programming language is embedded within another.
When a form is added to a Web page that submits data to a Web application, a malicious user may exploit the MIME format to append additional information to the message being sent, such as a new list of recipients or a completely different message body. Because the MIME format uses a carriage return to delimit the information in a message, and only the raw message determines its eventual destination, adding carriage returns to submitted form data can allow a simple guestbook to be used to send thousands of messages at once. A malicious spammer could use this tactic to send large numbers of messages anonymously.
More information on this topic, including examples and ways to avoid the vulnerability, can be found at the SecurePHP Wiki. However, this vulnerability is not limited to PHP; it can potentially affect any application that sends e-mail messages based on input from arbitrary users.
External links
- Email Headers Injection Using mail() Function (English)
- Email Headers Injection Using mail() Function (French)
| This computer network-related article is a stub. You can help Wikipedia by expanding it. |
This entry is from Wikipedia, the leading user-contributed encyclopedia. It may not have been reviewed by professional editors (see full disclaimer)




