in reply to Re^2: Simple .forward email parse
in thread Simple .forward email parse
Unless Email::Filter is making the results taint-safe, you are passing unvalidated data directly to a shell. Big time security no-no. It is better to open the file from within perl, and write escaped data to the file.
Depending on your mailer, you could also have a race condition on temp.log. Might be better to lock that file prior to writing to it.
--MidLifeXis
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^4: Simple .forward email parse
by docster (Novice) on Sep 17, 2008 at 15:08 UTC |