in reply to -T
That's not correct, but its one of the ways you need to un-taint input; run it through a safe-making RE and use only the matched part.$name = param('name'); $name =~ /(\w+)/; $safe_name = $1; # use $safe_name from here on out
a
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: -T
by jcpunk (Friar) on May 16, 2003 at 02:04 UTC |