Perl Monk, Perl Meditation | |
PerlMonks |
Re: Insecure $ENV{PATH} while running with -T switchby Corion (Patriarch) |
on Feb 29, 2016 at 07:50 UTC ( [id://1156420]=note: print w/replies, xml ) | Need Help?? |
See perltaint. The best approach is to either avoid invoking the shell by removing the redirection or to explicitly set up $ENV{PATH} to a trusted value. In your case, likely the following will suffice:
If the external program perl1.pl will be sending mail, maybe you also need to add the directory where the sendmail program lives to the path.
In Section
Seekers of Perl Wisdom
|
|