Re: FormMail Problem
- From: Gunnar Hjalmarsson <noreply@xxxxxxxxx>
- Date: Sun, 29 May 2005 11:48:25 +0200
Anno Siegel wrote:
Gunnar Hjalmarsson wrote:Unlike what Christopher stated
1) pipes to other programs can be opened also when taint mode is enabled, and
2) the /e modifier in the expressions for unescaping URI escaped strings
s/%([a-fA-F0-9][a-fA-F0-9])/pack("C", hex($1))/eg;
isn't dangerous.
[...]
It's funny. Normally, such incorrect statements on Perl would have resulted in several correcting follow-ups. Now, since they were made with the aim of discrediting FormMail, that did not happen.
Both have been pointed out in this thread befor now.
Yeah, by me. And you commented on the /e modifier, even if it was in a reply to Eric...
Maybe I shouldn't have said that. Probably not. :)
-- Gunnar Hjalmarsson Email: http://www.gunnar.cc/cgi-bin/contact.pl .
- References:
- FormMail Problem
- From: Olen R. Pearson
- Re: FormMail Problem
- From: Gunnar Hjalmarsson
- Re: FormMail Problem
- From: Tad McClellan
- Re: FormMail Problem
- From: Gunnar Hjalmarsson
- Re: FormMail Problem
- From: Anno Siegel
- FormMail Problem
- Prev by Date: Re: Regex help: delete text only if not within quotation marks
- Next by Date: FAQ 8.11 How do I decode encrypted password files?
- Previous by thread: Re: FormMail Problem
- Next by thread: Re: FormMail Problem
- Index(es):
Relevant Pages
|