If you allow %s, any CGI application can run on your Web server. This is a potential security risk. Do you want to allow ...