in reply to unlink taint
It's not the wildcard (.*) that makes the expression tainted, but rather what's in $upload_dir and/or $in{'imgid'} (if they originate from program-external input), so you need to untaint those. update: actually, it's the glob itself that, too, returns tainted data (with or without '*').
See perlsec for how to do it.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: unlink taint
by ikegami (Patriarch) on Dec 20, 2010 at 22:06 UTC | |
by Anonyrnous Monk (Hermit) on Dec 20, 2010 at 22:57 UTC | |
by ikegami (Patriarch) on Dec 20, 2010 at 23:11 UTC | |
|
Re^2: unlink taint
by toniax (Scribe) on Dec 20, 2010 at 21:52 UTC | |
by JavaFan (Canon) on Dec 20, 2010 at 21:54 UTC | |
by Anonyrnous Monk (Hermit) on Dec 20, 2010 at 21:55 UTC |