in reply to Re: -T switch & untaint - how to resolve errors?
in thread -T switch & untaint - how to resolve errors?
But I still get the error. Is the switch suppose to be turned off & it's purpose simply to make me aware that this issue needs to be addressed, or am I coding it incorrectly & thus not allowing the switch to realize that I'm untainting the data?untaint($name); untaint($siteName); open (FILE,">/$directory/tmpl/$name.tmpl"); print FILE $content; close(FILE); sub untaint { my $var = $_[0]; unless ($var =~ m/^(\w+)$/) { #allow filename to be [a-zA-Z0-9_] die("Tainted"); } return $var; }
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^3: -T switch & untaint - how to resolve errors?
by polettix (Vicar) on Apr 10, 2005 at 20:37 UTC | |
by Stenyj (Beadle) on Apr 10, 2005 at 21:11 UTC | |
by Joost (Canon) on Apr 10, 2005 at 21:46 UTC | |
by Stenyj (Beadle) on Apr 10, 2005 at 22:00 UTC | |
by doom (Deacon) on Apr 11, 2005 at 03:30 UTC | |
|
Re^3: -T switch & untaint - how to resolve errors?
by Stenyj (Beadle) on Apr 10, 2005 at 17:46 UTC |