in reply to Re^2: Calling perl from CGI
in thread Calling perl from CGI
does not contain user-supplied input. User-supplied input is what security-conscious hosts forbid. See perlsec for how it works.
Updated:
As other respondents have shown, your method would be ineffective even if it did not breach security, so I have deleted my original suggestions for putting an untainted module name between the backticks. The eval "use $module; 1" suggestion from lamp, besides having the advantage of actually working, is free of security concerns.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^4: Calling perl from CGI
by Anonymous Monk on Sep 07, 2008 at 07:55 UTC | |
|
Re^4: Calling perl from CGI
by Anonymous Monk on Sep 07, 2008 at 06:20 UTC |