Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: shell script cgi

From: mlh <mlh(at)zip.com.au>
Date: Sat Nov 16 2002 - 17:48:37 EST

I'm convinced there is no way in this particular statement, given that the var is in quotes.

All you're doing after all is echoing it, which only does one level of interpretation, which in this case is removing the quuotes.

Of course, some values may be more dangerous for statements further on in the code.

e.g.
HTTP_USER_AGENT='`cat /etc/passwd`'

Matt Received on Sat Nov 16 20:12:40 2002

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:37 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library