in reply to Re: Unexpected de-tainting with hash keys
in thread Unexpected de-tainting with hash keys

++ to you: not only is it shorter, it proves the significance of this bug as it shows execution of tainted data.

Apparently the stringification of hash keys is untainting this while providing no safety.

Eek indeed.

--Bob Niederman, http://bob-n.com
  • Comment on Re: Re: Unexpected de-tainting with hash keys

Replies are listed 'Best First'.
Re: Re: Re: Unexpected de-tainting with hash keys
by TGI (Parson) on Jul 11, 2003 at 02:28 UTC
    You nailed it. The hash key is a string and not a scalar. See my post below.


    TGI says moo