your Validate.pm doesn't untaint anything you can use.Now, that's sobering, Zaxo. All that work and it wasn't doing what I intended, My quest grows longers as I now have to figure out what you meant by:
You can pass your variables by reference to fix that, or else use the (\$) prototype.I'm hoping chromatic's code will shed some light.
In reply to Re: Re: Do I have to untaint all user input in a form?
by bradcathey
in thread Do I have to untaint all user input in a form?
by bradcathey
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |