#!/usr/bin/perl @referers = ('primepuzzle.com'); # Check Referring URL &check_url; # Retrieve Date &get_date; # Parse Form Contents &parse_form; # Check Required Fields &check_required; # Append To Log File &logit; # Return HTML Page or Redirect User &return_html; # NOTE re v1.91: This function is no longer intended to stop abuse; that # # functionality is now embedded in the checks made on @recipients and the # # recipient form field. # sub check_url { # Localize the check_referer flag which determines if user is valid. # local($check_referer) = 0; # If a referring URL was specified, for each valid referer, make sure # # that a valid referring URL was passed to FormMail. # if ($ENV{'HTTP_REFERER'}) { foreach $referer (@referers) { if ($ENV{'HTTP_REFERER'} =~ m|https?://([^/]*)$referer|i) { $check_referer = 1; last; } } } else { $check_referer = 1; } # If the HTTP_REFERER was invalid, send back an error. # if ($check_referer != 1) { &error('bad_referer') } } sub get_date { # Define arrays for the day of the week and month of the year. # @days = ('Sunday','Monday','Tuesday','Wednesday', 'Thursday','Friday','Saturday'); @months = ('January','February','March','April','May','June','July', 'August','September','October','November','December'); # Get the current time and format the hour, minutes and seconds. Add # # 1900 to the year to get the full 4 digit year. # ($sec,$min,$hour,$mday,$mon,$year,$wday) = (gmtime(time))[0,1,2,3,4,5,6]; $time = sprintf("%02d:%02d:%02d",$hour,$min,$sec); $year += 1900; # Format the date. # $date = "$days[$wday], $months[$mon] $mday, $year at $time"; } sub parse_form { # Define the configuration associative array. # %Config = ('filename','','logtext','','redirect','','required','','initials',''); # Determine the form's REQUEST_METHOD (GET or POST) and split the form # # fields up into their name-value pairs. If the REQUEST_METHOD was # # not GET or POST, send an error. # if ($ENV{'REQUEST_METHOD'} eq 'GET') { # Split the name-value pairs @pairs = split(/&/, $ENV{'QUERY_STRING'}); } elsif ($ENV{'REQUEST_METHOD'} eq 'POST') { # Get the input read(STDIN, $buffer, $ENV{'CONTENT_LENGTH'}); # Split the name-value pairs @pairs = split(/&/, $buffer); } else { &error('request_method'); } # For each name-value pair: # foreach $pair (@pairs) { # Split the pair up into individual variables. # local($name, $value) = split(/=/, $pair); # Decode the form encoding on the name and value variables. # # v1.92: remove null bytes # $name =~ tr/+/ /; $name =~ s/%([a-fA-F0-9][a-fA-F0-9])/pack("C", hex($1))/eg; $name =~ tr/\0//d; $value =~ tr/+/ /; $value =~ s/%([a-fA-F0-9][a-fA-F0-9])/pack("C", hex($1))/eg; $value =~ tr/\0//d; # If the field name has been specified in the %Config array, it will # # return a 1 for defined($Config{$name}}) and we should associate # # this value with the appropriate configuration variable. If this # # is not a configuration form field, put it into the associative # # array %Form, appending the value with a ', ' if there is already a # # value present. We also save the order of the form fields in the # # @Field_Order array so we can use this order for the generic sort. # if (defined($Config{$name})) { $Config{$name} = $value; } else { if ($Form{$name} ne '') { $Form{$name} = "$Form{$name}, $value"; } else { push(@Field_Order,$name); $Form{$name} = $value; } } } # The next six lines remove any extra spaces or new lines from the # # configuration variables, which may have been caused if your editor # # wraps lines after a certain length or if you used spaces between field # # names or environment variables. # $Config{'required'} =~ s/(\s+|\n)?,(\s+|\n)?/,/g; $Config{'required'} =~ s/(\s+)?\n+(\s+)?//g; # Split the configuration variables into individual field names. # @Required = split(/,/,$Config{'required'}); # ACCESS CONTROL FIX: Only allow ENV variables in @valid_ENV in # # @Env_Report for security reasons. # } sub check_required { # Localize the variables used in this subroutine. # local($require, @error); # The following insures that there were no newlines in any fields which # # will be used in the header. # # For each require field defined in the form: # foreach $require (@Required) { # If the required field is the email field, the syntax of the email # # address if checked to make sure it passes a valid syntax. # # Otherwise, if the required field is a configuration field and it # # has no value or has been filled in with a space, send an error. # if (defined($Config{$require})) { if ($Config{$require} eq '') { push(@error,$require); } } # If it is a regular form field which has not been filled in or # # filled in with a space, flag it as an error field. # elsif (!defined($Form{$require}) || $Form{$require} eq '') { push(@error,$require); } } # If any error fields have been found, send error message to the user. # if (@error) { &error('missing_fields', @error) } } sub return_html { # If redirect option is used, print the redirectional location header. # if ($Config{'redirect'}) { print "Location: $Config{'redirect'}\n\n"; } } sub logit { open(LOG,">>/home/primepzl/public_html/runlog/$Config{'filename'}"); if ($Config{'initials'} ne '') { print LOG "$Config{'initials'} - "; } # added 7/22/2011 # print LOG "$date (GMT) (subtract 4 for local time)\n\n"; print LOG "$Config{'logtext'}\n\n"; close (LOG); } # This function will convert <, >, & and " to their HTML equivalents. # sub clean_html { local $value = $_[0]; $value =~ s/\&/\&/g; $value =~ s/\</g; $value =~ s/>/\>/g; $value =~ s/"/\"/g; return $value; } sub error { # Localize variables and assign subroutine input. # local($error,@error_fields) = @_; local($host,$missing_field,$missing_field_list); if ($error eq 'bad_referer') { if ($ENV{'HTTP_REFERER'} =~ m|^https?://([\w\.]+)|i) { $host = $1; my $referer = &clean_html($ENV{'HTTP_REFERER'}); print <<"(END ERROR HTML)"; Content-type: text/html
Bad Referrer - Access Denied |
---|
The form attempting to use
FormMail
resides at $referer, which is not allowed to access
this cgi script. If you are attempting to configure FormMail to run with this form, you need to add the following to \@referers, explained in detail in the README file. Add '$host' to your \@referers array. A Free Product of Matt's Script Archive, Inc. |
FormMail |
---|
Copyright 1995 - 2002 Matt Wright Version 1.92 - Released April 21, 2002 A Free Product of Matt's Script Archive, Inc. |
---|
Error: Request Method |
---|
The Request Method of the Form you submitted did not match
either GET or POST. Please check the form and make sure the
method= statement is in upper case and matches GET or POST.
A Free Product of Matt's Script Archive, Inc. |
Error: Bad/No Recipient |
---|
There was no recipient or an invalid recipient specified in the data sent to FormMail. Please
make sure you have filled in the recipient form field with an e-mail
address that has been configured in \@recipients. More information on filling in recipient form fields and variables can be
found in the README file. A Free Product of Matt's Script Archive, Inc. |
Error: Bad Header Fields |
---|
The header fields, which include recipient, email, realname and subject were
filled in with invalid values. You may not include any newline characters in these parameters.
More information on filling in these form fields and variables can be
found in the README file. A Free Product of Matt's Script Archive, Inc. |
Error: Blank Fields |
---|
The following fields were left blank in your submission form:
These fields must be filled in before you can successfully submit the form. Please use your browser's back button to return to the form and try again. A Free Product of Matt's Script Archive, Inc. |