profile.php doesn't check email format profile.php doesn't check email format
 

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Main Menu

profile.php doesn't check email format

Started by Makc666, September 18, 2006, 11:08:52 AM

Previous topic - Next topic

0 Members and 2 Guests are viewing this topic.

Makc666

If you look into
register.php
you will find this one:
    if (!eregi("^[_\.0-9a-z\-]+@([0-9a-z][0-9a-z-]+\.)+[a-z]{2,6}$", $email)) $error .= '<li>' . $lang_register_php['err_invalid_email'];

If you look into
profile.php
you will not find any check for email format.
So users can enter any email they want like: testest.com or test@test