CGI Perl Question

From: Leonard Leblanc (lleblanc@emergeknowledge.com)
Date: 07/24/01


From: Leonard Leblanc <lleblanc@emergeknowledge.com>
To: security-basics@securityfocus.com
Subject: CGI Perl Question
Date: Mon, 23 Jul 2001 21:31:26 -0500
Message-Id: <01072321312600.18009@skeight>

Hello Everyone,

We are currently developing a new website with perl that consists of using
the HTML::Template module. In the beginning of this script there are
multiple constants defined which point to the template files using the
$ENV{DOCUMENT_ROOT} environment variable.

Does this present any more/less of a security risk then just hardcoding the
entire path into the script?

Thanks in advance.

-- 
Leonard Leblanc
Vice President - Technology
www.emergeknowledge.com



Relevant Pages

  • Re: CGI Perl Question
    ... Subject: CGI Perl Question ... I can't imagine any kind of hazards with leaving the %ENV variables as they ... specifically code the script to allow that. ...
    (Security-Basics)
  • Re: Tooltips ?
    ... DIV with a high zindex method works if script is enabled (about 90% ... The IE popup method works only in IE6 with script enabled. ... was to a publicly-posted website. ... They test it out in their browser, ...
    (microsoft.public.scripting.vbscript)
  • Cookie not working for CGI logon script
    ... The problem I'm having is that umzadmin.cgi script makes me login twice ... before I can use the website. ... sub loginScreen { ... &SortForm), last SWITCH if param; ...
    (comp.lang.perl.misc)
  • Re: Port Scanner Reports
    ... option, in combination with a good script in linux, or a batch script ... >Audit your website security with Acunetix Web Vulnerability Scanner: ... Cross site scripting and other web attacks before hackers do! ...
    (Pen-Test)
  • Re: Fehlerbehandlung
    ... >> Und jetzt verstehe ich den Verweis auf die Spracheinstellung nicht. ... dass das Script sich auf eine bestimmte Website ... > aktivieren/deaktivieren. ...
    (de.comp.lang.javascript)