in reply to cgi redirect
So what happens when one of the form values is "; rm -rf /" or "; cat /etc/passwd"?
Much safer to use remove_tree from File::Path instead. And check your input values, because they can still refer to parent directories! (File::Spec can help you manipulate the filenames.)
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: cgi redirect
by mitchreward (Acolyte) on Sep 30, 2014 at 09:05 UTC | |
by Anonymous Monk on Oct 01, 2014 at 01:34 UTC | |
by Anonymous Monk on Oct 01, 2014 at 21:08 UTC |