in reply to Own modules and tainted mode
Most likely you'll fare better by using an absolute path instead of a relative path:
use lib qw(/home/sites/feedback/cgi-bin);
I think that:
use lib dirname(dirname abs_path $0);
puts a tainted value into @INC because $0 can be under the control of an attacker (through symlinks or hardlinks).
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: Own modules and tainted mode
by haj (Vicar) on May 28, 2018 at 12:25 UTC | |
by PeterKaagman (Beadle) on May 28, 2018 at 13:50 UTC | |
by haj (Vicar) on May 28, 2018 at 14:51 UTC | |
by shmem (Chancellor) on May 28, 2018 at 22:53 UTC |