in reply to Re: Sending Data
in thread Sending Data
is not a good idea when 'datefile' is extracted from a form field, since this gives users the ability to write to any file on your file system via the classic backwards directory traversal trick (e.g. what if the input was "..\..\etc\passwd" ?). Whether or not the field is "hidden" is irrelevant.open (BOBIN, ">>$datefile") ...
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^3: Sending Data
by Midnite (Acolyte) on Aug 12, 2004 at 21:15 UTC |