4 ms·
I’ve always wondered if it’s possible to have a valid email address which is also an SQL injection attack, XSS or similar ?
by harryf 5y ago
I’ve always wondered if it’s possible to have a valid email address which is also an SQL injection attack, XSS or similar ?
- malinens 5y agoof course it can: https://security.stackexchange.com/a/106996 https://security.stackexchange.com/a/106996 One of our testers found XSS with email injection (RFC compkiant validation passed) in our website. And we are an e-mail company and should now better :D Never trust user input!
- goto11 5y agoProbably, since the local name part can be basically anything. But the way to prevent injection attacks is not to disallow or sanitize input, it is to escape correctly when interpolating strings in other languages.