Hacker News new | ask | show | jobs
by poizan42 3978 days ago
I'm slightly alarmed by urls such as: http://www.cs.toronto.edu/~graves/handwriting.cgi?text=Hej&s...

Relative paths allowed from user input is usually a HUGE warning sign. Are you sure I can't make it open arbitrary files? What happens to your cgi script if it reads a file in the wrong format?