>The problem is that a crafty user can still subvert your code by creating files that match, while you expected Cartesian Products to deliver. Taint mode prefers to err on caution, so you would need to either disable taint mode or untaint your glob results.
In reply to Re: Should non-filename glob() results still be tainted?
by Corion
in thread Should non-filename glob() results still be tainted?
by kcott
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |