in reply to Re^2: Using Regexp Patterns as Variables
in thread Using Regexp Patterns as Variables
What ikegami points out is also important to recognize. Anyone who can access to the site can feed in a URL with anything in it. As such, they may be able to choose a value for $1 with Dire Consequences.
For example, $1 = q{";system('shutdown -h now');"}
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^4: Using Regexp Patterns as Variables
by Rodster001 (Pilgrim) on Mar 18, 2009 at 17:26 UTC | |
by kyle (Abbot) on Mar 18, 2009 at 18:09 UTC | |
by ikegami (Patriarch) on Mar 18, 2009 at 19:45 UTC | |
by Rodster001 (Pilgrim) on Mar 18, 2009 at 20:28 UTC | |
by kyle (Abbot) on Mar 18, 2009 at 20:03 UTC | |
by ikegami (Patriarch) on Mar 18, 2009 at 21:13 UTC |