[23287] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Sendpage (Perl CGI) Remote Execution Vulnerability

daemon@ATHENA.MIT.EDU (Seth Arnold)
Wed Nov 28 17:19:30 2001

Date: Wed, 28 Nov 2001 12:59:30 -0800
From: Seth Arnold <sarnold@wirex.com>
To: bugtraq@securityfocus.com
Message-ID: <20011128125930.D7800@wirex.com>
Mail-Followup-To: bugtraq@securityfocus.com
Mime-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-md5;
	protocol="application/pgp-signature"; boundary="qN286NIOm1dtEdh0"
Content-Disposition: inline
In-Reply-To: <01112809243004.01160@bilbo>; from john.imrie@pa.press.net on Wed, Nov 28, 2001 at 09:24:30AM +0000

--qN286NIOm1dtEdh0
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Wed, Nov 28, 2001 at 09:24:30AM +0000, John Imrie wrote:
> > 	$message =3D~ s/[^\w\s]//g;
> $message =3D~ s/[^A-Za-z0-9]//g;

Note that these two are almost identical in the default locale, but the
first version also allows whitespace (maybe useful :) and more
international-friendly characters such as: =E1=EE=E5=EF=E9=E1=F0 ....

Cheers

--=20
"Soldiers quartered in a populous town will always occasion two mobs
where they prevent one. They are wretched conservators of the peace."
-- John Adams

--qN286NIOm1dtEdh0
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE8BVAx1XMg6PgdEDQRAnzpAKDuNBrhX2iAZLnm2srHiV6GgT+wwACggrQE
A7SkNG0SbsZyoELKwGiisic=
=zX+i
-----END PGP SIGNATURE-----

--qN286NIOm1dtEdh0--

home help back first fref pref prev next nref lref last post