"... the user doesn't actually do anything but click on the radio button to indicate which report they want.
Even though you "narrow the choices" on the interface, the user doesn't have to use the interface. Instead they could submit a GET query directly:
or use a web bot, etc. Even though 99% of the people don't know about this, the 1% that does is 100% of the devious people you need to worry about. ;) Cheers :)# contrived example http://foo.com/cgi-bin/form.cgi?rpt_id=../../../etc/password
jeffa
L-LL-L--L-LL-L--L-LL-L-- -R--R-RR-R--R-RR-R--R-RR B--B--B--B--B--B--B--B-- H---H---H---H---H---H--- (the triplet paradiddle with high-hat)
In reply to 5Re: HTML::Template, CGI - concatenating strings & variables
by jeffa
in thread HTML::Template, CGI - concatenating strings & variables
by Lori713
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |