nextguru has asked for the wisdom of the Perl Monks concerning the following question:
I have several CGI scripts running with the -T flag that have broken after recently upgrading the perl installation from 5.8 to 5.10 on my development web server. The problem is when writing tainted information to a filehandle with a formerly tainted file name. This makes no sense to me, but untainting the information being written to the file gets rid of the 'Insecure dependency in printf...' messages.
What am I missing that writing tainted data is now a problem?
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Taint, CGI and perl 5.10
by ikegami (Patriarch) on Mar 10, 2010 at 21:22 UTC | |
by nextguru (Scribe) on Mar 11, 2010 at 03:52 UTC | |
by ikegami (Patriarch) on Mar 11, 2010 at 05:21 UTC | |
by nextguru (Scribe) on Mar 11, 2010 at 05:41 UTC | |
by derby (Abbot) on Mar 11, 2010 at 12:10 UTC | |
by rowdog (Curate) on Mar 11, 2010 at 12:44 UTC | |
by nextguru (Scribe) on Mar 11, 2010 at 02:15 UTC | |
by ikegami (Patriarch) on Mar 11, 2010 at 03:17 UTC | |
|
Re: Taint, CGI and perl 5.10
by SilasTheMonk (Chaplain) on Mar 10, 2010 at 21:08 UTC | |
|
Re: Taint, CGI and perl 5.10
by BrowserUk (Patriarch) on Mar 10, 2010 at 19:56 UTC |