Think about Loose Coupling | |
PerlMonks |
do not use this script in a public environment!by antihec (Sexton) |
on Jun 02, 2000 at 16:46 UTC ( [id://16002]=note: print w/replies, xml ) | Need Help?? |
I did a little audit of this app Here's what I found:
calendar.pl
showDate.pl
alterDate.pl I didn't play with action=rem, but it looks like it let's you remove any line containing a ':' from any file writable by the user the webserver is running as. (such as logfiles, if you want to hide your traces from playing with action=Add%20new%20entry) so, as a bottom line, please be sure to check user input in your cgis, esp. when you post them to some public place. You never know just who's gonna use them in what surroundings.
In Section
Code Catacombs
|
|