in reply to Insecure dependency message ?
The line you get the error involves $outfile. Where are $basedir, $month, $year and $day from? Have you untainted your foreign source (user input, stream input, file input) variables? If you have NO clue what I mean, then i suggest doing a "man perlsec" and reading up on the taint section. They talk about untainting and the likes.$month = $month + 1; #localtime returns mth as 0 to 11 $outfile = sprintf "%s/%4d-%2.2d-%2.2d-", $base_dir, $year + 1900, $month, $day;
That's what the -T in your shebang (firstline) is about.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: Insecure dependency message ?
by peterr (Scribe) on Jan 06, 2004 at 03:41 UTC | |
by exussum0 (Vicar) on Jan 06, 2004 at 04:06 UTC | |
by peterr (Scribe) on Jan 06, 2004 at 04:52 UTC | |
by exussum0 (Vicar) on Jan 06, 2004 at 04:57 UTC | |
by peterr (Scribe) on Jan 07, 2004 at 01:21 UTC | |
by duff (Parson) on Jan 06, 2004 at 04:10 UTC | |
by peterr (Scribe) on Jan 06, 2004 at 04:40 UTC |