in reply to Re: The danger of hidden fieldsin thread The danger of hidden fields
Also if you are trusting user input to name a file, what if the user names a "file" (with proper encoding of course) something like | rm -rf /?