 
                            ...
| CERT Perl Secure Coding Standard | IDS30-PL. Exclude user input from format strings | 
| Injection [RST] | |
| CWE-134, Uncontrolled format stringFormat String | 
Bibliography
| [API 2006] | |
| Chapter 6, "Formatted Output" | |
| [Seacord 2015] | IDS06-J. Exclude unsanitized user input from format strings LiveLesson | 
...