by saltybeagle » Fri Mar 30, 2007 11:16 am
Well, for email harvesting, I would say a little.... but having a public form out there which uses formmail script is a little hazardous if the script is not properly secured.
By including the To: email address within the source of the form, this may prevent search engines from indexing the email address -- but the formmail script is (usually) vulnerable to accepting any email address posted to it to send a message to.
So keep in mind, the post values, even if they are hidden input elements can be spoofed.
Brett Bieber
