in reply to Running pscp from cgi-script in Windows
You know you might be vulnerable to a cross-site scripting attack. That's what -T is warning you about. What would happen if someone was to figure out how to pass "junk | del *.*" as that store parameter. Or even worse something like "whatever | putty.exe ...". Be sure you are running this on a server that is isolated from the Internet.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: Running pscp from cgi-script in Windows
by redrafiki (Initiate) on Oct 27, 2010 at 14:24 UTC |