>>>>> "craigs1775" == craigs1775
<craigs1775 yahoo.com> writes:
craigs1775> Am migrating an existing Perl site to new
system. (Currently on
craigs1775> FreeBSD 4.3, Apache 1.3.19, Perl 5.005_03)
I'm using a fresh install
craigs1775> of FreeBSD 6.1, Apache-2.2.3 &
Perl-5.8.8.
craigs1775> This site allows and adminstrator to run Perl
scripts. One of these
craigs1775> pulls e-mail addresses from a PostgreSQL
database, grabs a text file
craigs1775> (the message body) and sends out e-mails.
The latest DBI taints the data coming from a database, and
if you're using
that in your very dangerous command, it is rightfully
protecting you
from shooting yourself in the foot.
In other words, you've been lucky up to this point, and
finally one
more hole has been closed.
Look into Email::Send in the CPAN to replace your
command-line mail
invocation.
--
Randal L. Schwartz - Stonehenge Consulting Services, Inc. -
+1 503 777 0095
<merlyn stonehenge.com> <URL:http://www.ston
ehenge.com/merlyn/>
Perl/Unix/security consulting, Technical writing, Comedy,
etc. etc.
See PerlTraining.Stonehenge.com for onsite and
open-enrollment Perl training!
Unsubscribing info is here: h
ttp://help.yahoo.com/help/us/groups/groups-32.html
Yahoo! Groups Links
<*> To visit your group on the web, go to:
http://g
roups.yahoo.com/group/perl-beginner/
<*> Your email settings:
Individual Email | Traditional
<*> To change settings online go to:
http
://groups.yahoo.com/group/perl-beginner/join
(Yahoo! ID required)
<*> To change settings via email:
mailto:perl-beginner-digest@yahoogroups.com
mailto:perl-beginner-fullfeatured@yahoogroups.com
<*> To unsubscribe from this group, send an email to:
perl-beginner-unsubscribe@yahoogroups.com
<*> Your use of Yahoo! Groups is subject to:
http://docs.yahoo.c
om/info/terms/
|