BTW, on a *NIX system one can put rubbish into __FILE__ via
% ln -s myscript.pl evil-char-sequence.plNot as simple as 'SOMEVAR=evil-char-sequence ./myscript.pl', but still possible (but an unlikely attack vector, and not available to a remote attacker).
In reply to Re^2: How to safely define a CGI program's application base directory
by Dallaylaen
in thread How to safely define a CGI program's application base directory
by ddmiller
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |