my $file_cmd_output = `file $fn`;
$fn is tainted and doesn't this give them the chance to sneak a command in via $fn? Need to make sure $fn is clean.
Joe.
In reply to Re: Re(2) (ichimunki): Security issues when allowing file upload via CGI
by nufsaid
in thread Security issues when allowing file upload via CGI
by George_Sherston
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |