in reply to Creating dynamically named CGIs
Make jolly sure that you are checking the contents of param('file'). In particular, make sure that data.cgi?file=../../../../../../etc/passwd does not output bad things to the user.
You may have done this already, or you may trust your authenticated users, but it never hurts to be careful... I have just been bitten in the ass by this, so I speak from bitter (in)experience!
dave hj~
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: Creating dynamically named CGIs
by ryan (Pilgrim) on Feb 13, 2002 at 15:01 UTC |