But <samp>do EXPR</samp> is an eval! The docs say:
It goes on to list some differences.is just likedo 'stat.pl';...scalar eval `cat stat.pl`;
The point about taint mode is not letting your program execute (some, not all!) potentially dangerous operations. Replacing an eval with do doesn't do that...
In reply to Re: Re: Laundering tainted 'eval'
by ariels
in thread Laundering tainted 'eval'
by bodhidharma
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |