in reply to Re: Re: Not my first program, but the first I'll share...
in thread Not my first program, but the first I'll share...
"One who tries to avoid disagreeable situations by refusing to face them."
If you insist on letting users give you filenames, at very least, use the three-argument version of open.
I seem to remember reading somewhere that .htaccess is not infallable as a security measure. I can't seem to find the link now though.
I still think you should give the user a filename list, and read which item they selected from the list, by some index value. That way you only pass index values as input from the CGI script, and then you look up what file that index pertains to, and open the file yourself. Such a setup eliminates any possibility of the user specifying a dirty filename.
Dave
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: Re: Re: Not my first program, but the first I'll share...
by pekkhum (Sexton) on Oct 27, 2003 at 22:39 UTC |