in reply to Bad code from the trenches
Security hole: $dest is in double quotes. If it contains something like @{[ arbitrary Perl code here]} then that Perl code will be executed. (Code interpolation in double quote context.)
This one is clearly false. The other one (2-arg open) is indeed a security bug.
(Update: formatting)
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: Bad code from the trenches
by dragonchild (Archbishop) on Mar 14, 2005 at 13:52 UTC | |
by Corion (Patriarch) on Mar 14, 2005 at 13:54 UTC | |
by dragonchild (Archbishop) on Mar 14, 2005 at 14:03 UTC | |
by Joost (Canon) on Mar 14, 2005 at 14:08 UTC | |
by dragonchild (Archbishop) on Mar 14, 2005 at 14:16 UTC | |
|