in reply to Re: Quotes In CGI
in thread Quotes In CGI
script.cgi?x=1;system('rm%20-rf%20/etc/');print%20'gotcha!This would eval (I think -- it's not tested), and do some potentially nasty things. I'm not devious enough to come up with something really nasty to do in a system call, but you get the idea... jpt
|
---|
Replies are listed 'Best First'. | |
---|---|
Re: Re: Re: Quotes In CGI
by jlongino (Parson) on Oct 08, 2002 at 03:37 UTC |