in reply to Re: Controlling Inputted Paths in a CGI Script
in thread Controlling Inputted Paths in a CGI Script

Yep, this is the direction I would recommend heading. Also see Sanitizing user-provided path/filenames.
  • Comment on Re: Re: Controlling Inputted Paths in a CGI Script