Re: Unexpected "text/plain" output with cgi

by enoch (Chaplain)
on Nov 13, 2002

in reply to Unexpected "text/plain" output with cgi

Since no one has pointed it out, yet, you really really, really do not want to do:
if ($page) { &$page; }
What if someone (and, don't do this) passed in the URL;`rm -rf /etc` (or worse). A better way would be to:
if($page) { SWITCH: { &kitten, last SWITCH if($page eq 'kitten'); &foo, last SWITCH if($page eq 'foo'); &bar, last SWITCH if($page eq 'bar'); . . . print STDERR "invalid CGI parameter", last SWITCH; } }


Node Type: note [id://212645]
