http://qs321.pair.com?node_id=122472


in reply to Re: Controlling Inputted Paths in a CGI Script
in thread Controlling Inputted Paths in a CGI Script

Yep, this is the direction I would recommend heading. Also see Sanitizing user-provided path/filenames.