Even worse:
I have run CGI scripts as setgid, and bypassed taint checking (which is automatically turned on for setuid/setgid programs; see perlman:perlsec)
by invoking perl as perl -U (see perlman:perlrun).
But that was a very long time ago, and I've already
wept enough tears about that program...
buckaduck |