-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathresult.php
executable file
·134 lines (108 loc) · 3.44 KB
/
result.php
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
<!DOCTYPE html>
<?php
$email_from = $_POST['email'];
$comment = $_POST['comment'];
$comment_entered = true;
//Validate first
if(empty($comment))
$comment_entered = false;
if(IsInjected($email_from))
{
echo "Bad email value";
exit;
}
$email_subject = "Yik Yak Feedback";
$email_body = $comment;
$to = "[email protected]";//<== update the email address
$headers = "From: $email_from \r\n";
//Send the email!
if ($comment_entered) {
mail($to,$email_subject,$email_body,$headers);
$mailed = true;
}
// Function to validate against any email injection attempts
function IsInjected($str)
{
$injections = array('(\n+)',
'(\r+)',
'(\t+)',
'(%0A+)',
'(%0D+)',
'(%08+)',
'(%09+)'
);
$inject = join('|', $injections);
$inject = "/$inject/i";
if(preg_match($inject,$str))
{
return true;
}
else
{
return false;
}
}
?>
<html>
<head>
<!-- Basic Page Needs
================================================== -->
<meta charset="utf-8">
<title>Hawk Yak | Feedback</title>
<meta name="description" content="Yik Yak feed of Lehigh University">
<meta name="author" content="Deep Sheth & Adam Knuckey">
<!-- CSS
================================================== -->
<link href='http://fonts.googleapis.com/css?family=Cabin:500|Exo:800' rel='stylesheet' type='text/css'>
<link rel="stylesheet" href="./static/cobblestone.css">
<link rel="stylesheet" href="./static/style.css">
<!-- JS
================================================== -->
<script src="http://ajax.googleapis.com/ajax/libs/jquery/2.1.1/jquery.min.js"></script>
<script src="./Static/normal_script.js"></script>
<!-- Favicons
================================================== -->
<link rel="icon" href="" />
<!-- Mobile Specific Metas
================================================== -->
<meta name="viewport" content="width=device-width, initial-scale=1, maximum-scale=1">
<!-- Analytics
================================================== -->
</head>
<body id="faq">
<a id="top-icon" href="index.html">Yak Feed</a>
<header id="top">
<div class="container">
<div class="row">
<h1><big><big>Feedback</big></big></h1>
</div>
</div>
</header>
<section class="section">
<div class="container">
<hr>
<?php
if (!$comment_entered) {
echo ('<h2>ERROR. The comment box was empty.</h2>');
} elseif ($mailed) {
echo ('<h2>Thank you! Your feedback has been sent.</h2>');
} else {
echo ('<h2>ERROR. No feedback was submitted.</h2>');
}
?>
<hr>
<div class="section">
<a href="faq.php" class="btn btn-large btn-primary btn-block pull-center col-3">Back to FAQ</a>
</div>
</div>
</section>
<script>
(function(i,s,o,g,r,a,m){i['GoogleAnalyticsObject']=r;i[r]=i[r]||function(){
(i[r].q=i[r].q||[]).push(arguments)},i[r].l=1*new Date();a=s.createElement(o),
m=s.getElementsByTagName(o)[0];a.async=1;a.src=g;m.parentNode.insertBefore(a,m)
})(window,document,'script','//www.google-analytics.com/analytics.js','ga');
ga('create', 'UA-56753882-1', 'auto');
ga('send', 'pageview');
</script>
</body>
</html>