It's not the wildcard (.*) that makes the expression tainted, but rather what's in $upload_dir and/or $in{'imgid'} (if they originate from program-external input), so you need to untaint those. update: actually, it's the glob itself that, too, returns tainted data (with or without '*').
See perlsec for how to do it.
In reply to Re: unlink taint
by Anonyrnous Monk
in thread unlink taint
by toniax
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |