http://www.perlmonks.org?node_id=905046


in reply to Re^4: Executing a string as a Perl command
in thread Executing a string as a Perl command

eval is the wrong answer since it can run arbitrary code

If the user gives you some form of # rm -rf * ~ /, a lot of your files get deleted

Replies are listed 'Best First'.
Re^6: Executing a string as a Perl command
by ctilmes (Vicar) on May 16, 2011 at 13:25 UTC
    The OP said nothing about a user supplying the string. We pointed out that there are security concerns if you don't trust the string.

    If you want to run arbitrary code supplied by a 100% trusted source at runtime, what would you use other than eval?