From: Matt S Trout Date: Mon, 26 Dec 2022 14:38:05 +0000 (+0000) Subject: quote - eval X-Git-Url: http://git.shadowcat.co.uk/gitweb/gitweb.cgi?a=commitdiff_plain;h=181bd671c754b14ea9bb339ea5557788ffc9907d;p=scpubgit%2Fmst-quotefile.git quote - eval --- diff --git a/quotefile b/quotefile index 2da8ac6..25135ed 100644 --- a/quotefile +++ b/quotefile @@ -15205,3 +15205,8 @@ Despair for the future of humanity. Buy Whiskey. < erry> i think i'd forgotten what sun is < Altreus> I WANNA FEEL WHAT SUN IS ♫ < cat-xeger> Stay away from the fusion reactor, dammit! +% + after the day I discovered a core handler in a CGI::Application + codebase deployed under mod perl that did part of its dispatch by + doing a string eval of an unvalidated and unescaped query parameter + very little scares me anymore