Forum Moderators: open
There seems to be header injection issues in both ASP and PHP. At the moment, we've added javascript validation that checks whether the email address is valid or not. Ideally, we're going to perform the same validation on the server side as well.
We're looking for help on how to replicate the problem (before we implement any solutions). Any thoughts?