Ok I may get flamed for this, but here it goes:
I've got a script in which I need to be able to open a user-specified directory. I take the variable from the CGI program and compare it with a listing of the valid subdirectories and let it pass if it matches. Is this ok security-wise?