in reply to Re: Making webpages from a single CGI
in thread Making webpages from a single CGI
What if the request is something like http://www.cheese.com/foo?file=image.jpg%22%3E%3C!--%20#include%0Afile=%22/etc/passwd%22--%3E%3Cspan%20id=%22foo
Alright, I'm picking on you for comments like "This never works" and "Just for fun". If you're not sure what something does, please find out before you recommend it to someone else.Using CGI.pm will not fix the exploitish URI above, though it will prevent you from hand rolling form parsing code. Reading through perldoc perlsec won't automatically fix the potential security hole, but it will help you think in terms of how to minimize the risk. ©
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: Re: Making webpages from a single CGI
by Anonymous Monk on Oct 04, 2001 at 05:36 UTC | |
by strfry() (Monk) on Oct 05, 2001 at 16:26 UTC |