in reply to User regexps
You should use taint.
You should be aware of what use re 'eval' allows you to do with regular expressions.
And you should of course be aware of source code injection. Suppose the user specifies: "a/; system( 'some evil command' ); m/a" and your code is:
you're in deep trouble.eval "m/$query/";
Liz
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: User regexps
by Abigail-II (Bishop) on Jan 14, 2004 at 15:39 UTC | |
by dd-b (Pilgrim) on Jan 14, 2004 at 18:22 UTC |