Beefy Boxes and Bandwidth Generously Provided by pair Networks
Don't ask to ask, just ask
 
PerlMonks  

Re: Unexpected "text/plain" output with cgi

by enoch (Chaplain)
on Nov 13, 2002 at 17:48 UTC ( #212645=note: print w/replies, xml ) Need Help??


in reply to Unexpected "text/plain" output with cgi

Since no one has pointed it out, yet, you really really, really do not want to do:
if ($page) { &$page; }
What if someone (and, don't do this) passed in the URL http://www.robotskull.com/cgi-bin/index.cgi?page=kittens;`rm -rf /etc` (or worse). A better way would be to:
if($page) { SWITCH: { &kitten, last SWITCH if($page eq 'kitten'); &foo, last SWITCH if($page eq 'foo'); &bar, last SWITCH if($page eq 'bar'); . . . print STDERR "invalid CGI parameter", last SWITCH; } }

Enoch

Log In?
Username:
Password:

What's my password?
Create A New User
Node Status?
node history
Node Type: note [id://212645]
help
Chatterbox?
[hippo]: Anyone able to get to https://deps. cpantesters.org/? Not even getting a connection from here.
[choroba]: Down for everyone of just me
[shmem]: "Problem loading page" here
[marto]: seems down
[planetscape]: Able to ping but not connect with either Opera or Firefox
[thanos1983]: same here...
[choroba]: marto ;-)
[Discipulus]: after an error now is back
[shmem]: looks like a 302 loop - "The document has moved here"
[Discipulus]: ..but only http not https

How do I use this? | Other CB clients
Other Users?
Others taking refuge in the Monastery: (12)
As of 2018-02-20 11:50 GMT
Sections?
Information?
Find Nodes?
Leftovers?
    Voting Booth?
    When it is dark outside I am happiest to see ...














    Results (271 votes). Check out past polls.

    Notices?