.
, ../
, //
, or the name of the directory that contains your CGI programs.
eval
statement in Perl and the Bourne shell. If the reader sends input that begins with a semicolon (;), they may be able to get your system to perform any command they like. Likewise, if you use calls to popen()
and system()
, make sure you put a backslash (\) before any characters with special meaning in the shell that will run.
server.log
file.