in reply to Yet Another Cargo Cult non-use of CGI.pm
in thread Upload Security (strip ../, etc.)
Actually, this in one of the few hand-rolled CGI parameter parsers I've seen which doesn't break multi-select fields (well, I suppose it might do if the values contained '|' characters - but it's still better than most!)
Your other points are spot on tho.
--
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
RE: RE: Yet Another Cargo Cult non-use of CGI.pm
by merlyn (Sage) on Aug 01, 2000 at 01:06 UTC |