<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>PHPDeveloper.org</title>
    <link>http://www.phpdeveloper.org</link>
    <description>Up-to-the Minute PHP News, views and community</description>
    <language>en-us</language>
    <pubDate>Sun, 19 May 2013 01:29:11 -0500</pubDate>
    <ttl>30</ttl>
    <item>
      <title><![CDATA[Sanisoft Blog:  Email component in CakePHP is now Header Injection safe]]></title>
      <guid>http://www.phpdeveloper.org/news/8253</guid>
      <link>http://www.phpdeveloper.org/news/8253</link>
      <description><![CDATA[<p>
This <a href="http://www.sanisoft.com/blog/2007/07/14/email-component-in-cakephp-is-now-header-injection-safe/">new post</a> on the Sanisoft blog has some good news for CakePHP developers concerning the bundled email component - it now can be made header injection safe.
</p>
<blockquote>
In Cheesecake 1.x we had used our home grown component for sending emails. Having learned our lessons from the headaches of Pixelpost team due to email header injection attacks in their comment mailing code we had taken precautions to make our code safe from such attacks.
</blockquote>
<p>
They <a href="https://trac.cakephp.org/ticket/2855">proposed an update</a> to the CakePHP functionality to integrate this solution on a more permanent basis.
</p>]]></description>
      <pubDate>Mon, 16 Jul 2007 13:48:00 -0500</pubDate>
    </item>
  </channel>
</rss>
