in reply to Mail::Mailer and difficulty with -T taint mode
Insecure $ENV{%s} while running %sDoes that help?(F) You can't use system(), exec(), or a piped open in a setuid or setgid script if any of $ENV{PATH}, $ENV{IFS}, $ENV{CDPATH}, $ENV{ENV} or $ENV{BASH_ENV} are derived from data supplied (or potentially supplied) by the user. The script must set the path to a known value, using trustworthy data. See perlsec.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: Mail::Mailer and difficulty with -T taint mode
by davido (Cardinal) on Oct 12, 2003 at 10:58 UTC | |
by sgifford (Prior) on Oct 12, 2003 at 14:39 UTC | |
by PodMaster (Abbot) on Oct 12, 2003 at 11:22 UTC | |
by Nkuvu (Priest) on Nov 21, 2003 at 19:55 UTC |