in reply to Perl, CGI, and Security

You might want to check SecurityFocus. I did a quick search there for "perl" and came up with quite a few examples of how badly written perl had created security holes. Here's a couple:

  • CVSWeb insecure perl "open" vulnerability
  • Matt Kruse Calendar Arbitrary Command Execution Vulnerability
  • Ultimate Bulletin Board Arbitrary Command Execution Vulnerability

    There's more under those search results and I'm sure if you searched for stuff like "CGI" and ".pl" etc you'd find hundreds more.

    Incidentally, I chose "Entire Site" the first time I searched and got no results. The links above are from searching the vulnerabilities.