in reply to Re^2: How to safely define a CGI program's application base directory
in thread How to safely define a CGI program's application base directory

If attacker has access to filesystem (or %ENV) the game is already over , nothing to worry about :)
  • Comment on Re^3: How to safely define a CGI program's application base directory