4 ms·
imo it's best to just avoid it altogether. Requirements change, and what was once a trusted input can become untrusted input.
by remus 2y ago
imo it's best to just avoid it altogether. Requirements change, and what was once a trusted input can become untrusted input.
- rat87 2y agoGenerally you shouldn't be passing random data from the web to shell scripts. Maybe I haven't done the right type of work but having to deal with fidlg bits it's much more likely not passing it to be shell will cause issues (with stuff like executable paths)