in reply to Re^2: Taint mode and DBI
in thread Taint mode and DBI

i'm not a master of DBI nor a Taint one, but you should understand the distinction between them. you MUST use placeholders when DBI is involved. is a good practice should never be avoided even if you are the only user of the application, in my opinion and experience.

Taint mode is whole another story. it assume that all, and i say all, input coming from outside the source code of your Perl program is evil. Evilness is viral so if you mix presumed-evil-data with other data the result is another evil-presumed data. Taint mode is explained also in Modern Perl.

HtH
L*
There are no rules, there are no thumbs..
Reinvent the wheel, then learn The Wheel; may be one day you reinvent one of THE WHEELS.