From: Dave C. <da...@da...> - 2002-05-08 08:27:21
|
On Wed, May 08, 2002 at 08:04:22AM +0100, Nick Cleaton (ni...@cl...) wrote: > On Wed, May 08, 2002 at 01:01:03AM -0700, Nick Cleaton wrote: > > > > Modified Files: > > search.pl > > Log Message: > > * fixed some XSS holes > > I've used a tied hash for this, so that expressions can be > escaped into here documents with $E{$foo} rather than the > less elegant ${\( escape_html($foo) )}. > > But that might be too complicated for out intended audience. No, that's fine by me. Doesn't need to be simple - as long as it's correct. I've released a new version of simple (and also formmail which seemed to have some outstanding updates). Dave... -- Don't dream it... be it |