On 9 Jun 2001, at 7:10, Randal L. Schwartz wrote:

> But that doesn't matter.  If you don't plan for it, someone will
> create a path with a newline to DELIBERATELY break your code
> and potentially open up a security hole.

Harrumph.  If someone is creating paths on *my* system (yes, 
even under CGI control), I've already *got* a security hole.
 
> So yes, I take newlines in paths seriously.  You can't be an ostrich
> about them burying your head in the sand.  That's not secure, and you
> will be hacked.

Ostriches don't really bury their heads in the sand, you know...
-- 
Karen J. Cravens ([EMAIL PROTECTED])

Reply via email to