form action:mailto & attachments

Posted on 2003-03-30
Medium Priority
Last Modified: 2010-05-18
Hi ...

I have two questions:

1. How secure and reliable is the method of placing attachments using the form action mailto:? If so, an answer to question 2 would be helpful. If not, other suggestions would be great.

2.What is missing from this code, as I cannot get the data into an email with an attachment.

<form method="post" action="mailto:myname@something.com" enctype="multipart/form-data">
<input type="file" name="attachedimage2" id="attachedimage2" size="40" accept="image/*" style="color: #010425; background-color: #e6e6e6; border-color: #666600; border-color: #b8860b; font-family: verdana; font-size: 10pt" />

Question by:pjbyrne
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions

Accepted Solution

russellshome earned 750 total points
ID: 8233264
1. It is not so much insecure as impossible - and rightly so since if it was possible, it would be insecure.

2. Same problem! If you could set the value of an input type="file" rather than the user selecting a file then that would be insecure so it is impossible.

What file are you trying to get a user to email?
  Don't bother trying this in a web context because if you can, you would have found a security hole that should be fixed.

Or do you want to email a file on the web server to the user?
You will need server side code such as ASP using CDO to achieve this.
LVL 17

Expert Comment

ID: 8233299
(1) Very secure - the file would never leave the users computer. mailto: is horribly unreliable at the best of times, I've never seen it work with file attachments. If it did work (or if you used another method) it would be as secure as email normally is (i.e. not so secure that you would want to send credit card details by it).

(2) A form handler that can actually cope with file attachments.


should give you pointers.

Author Comment

ID: 8234338
Thanks. I will look into server side code and the form handler links.

Expert Comment

ID: 8235493

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Have you tried to learn about Unicode, UTF-8, and multibyte text encoding and all the articles are just too "academic" or too technical? This article aims to make the whole topic easy for just about anyone to understand.
Originally, this post was published on Monitis Blog, you can check it here . In business circles, we sometimes hear that today is the “age of the customer.” And so it is. Thanks to the enormous advances over the past few years in consumer techno…
The viewer will the learn the benefit of plain text editors and code an HTML5 based template for use in further tutorials.
HTML5 has deprecated a few of the older ways of showing media as well as offering up a new way to create games and animations. Audio, video, and canvas are just a few of the adjustments made between XHTML and HTML5. As we learned in our last micr…
Suggested Courses

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question