View Single Post
  #8 (permalink)  
Old 06-30-2004, 11:47 AM
nelsonez's Avatar
nelsonez nelsonez is offline
WebProWorld Pro
 
Join Date: Feb 2004
Location: St. Paul, MN
Posts: 108
nelsonez RepRank 0
Default Reasons to not allow "/" and "`" charact

I am not entirely sure how or what code would be used but I did read the following from a white paper on web security.

It might allow someone to type in something like this into the form "print `cat /etc/passwd`" (or worse) as the input string.

Another common security breach is to do backward directory traversing using ../


Eric

<><><><><><><><><><>
My two companies: Affordable Web Makeovers | Kanantik – Belize Resort
Reply With Quote