Version 2.3.6
This commit is contained in:
1 parent
a3bb603c96
commit
19b38c7c74
764 files changed
+143731
-118164
No files matched your search
@@ -2,22 +2,14 @@
|
||||
|
||||
/*
|
||||
+--------------------------------------------------------------------------
|
||||
| Invision Power Board 2.2.2
|
||||
| Invision Power Board
|
||||
| =============================================
|
||||
| by Matthew Mecham
|
||||
| (c) 2001 - 2006 Invision Power Services, Inc.
|
||||
| http://www.invisionpower.com
|
||||
| =============================================
|
||||
| Web: http://www.invisionboard.com
|
||||
| http://www.ibresource.ru/products/invisionpowerboard/
|
||||
| Time: Monday 05th of March 2007 10:10:55 PM
|
||||
| Release: e3790216629e5a2aaf37070b32237f06
|
||||
| Licence Info: http://www.invisionboard.com/?license
|
||||
| http://www.ibresource.ru/license
|
||||
+---------------------------------------------------------------------------
|
||||
| INVISION POWER BOARD ÍÅ ßÂËßÅÒÑß ÁÅÑÏËÀÒÍÛÌ ÏÐÎÃÐÀÌÌÍÛÌ ÎÁÅÑÏÅ×ÅÍÈÅÌ!
|
||||
| Ïðàâà íà ÏÎ ïðèíàäëåæàò Invision Power Services
|
||||
| Ïðàâà íà ïåðåâîä IBResource (http://www.ibresource.ru)
|
||||
+---------------------------------------------------------------------------
|
||||
| > $Date: 2005-10-10 14:03:20 +0100 (Mon, 10 Oct 2005) $
|
||||
| > $Revision: 22 $
|
||||
@@ -256,7 +248,7 @@ class class_upload
|
||||
$FILE_NAME = isset($_FILES[ $this->upload_form_field ]['name']) ? $_FILES[ $this->upload_form_field ]['name'] : '';
|
||||
$FILE_SIZE = isset($_FILES[ $this->upload_form_field ]['size']) ? $_FILES[ $this->upload_form_field ]['size'] : '';
|
||||
$FILE_TYPE = isset($_FILES[ $this->upload_form_field ]['type']) ? $_FILES[ $this->upload_form_field ]['type'] : '';
|
||||
|
||||
|
||||
//-------------------------------------------------
|
||||
// Naughty Opera adds the filename on the end of the
|
||||
// mime type - we don't want this.
|
||||
@@ -275,7 +267,15 @@ class class_upload
|
||||
or !$_FILES[ $this->upload_form_field ]['size']
|
||||
or ($_FILES[ $this->upload_form_field ]['name'] == "none") )
|
||||
{
|
||||
$this->error_no = 1;
|
||||
if( $_FILES[ $this->upload_form_field ]['error'] == 2 )
|
||||
{
|
||||
$this->error_no = 3;
|
||||
}
|
||||
else
|
||||
{
|
||||
$this->error_no = 1;
|
||||
}
|
||||
|
||||
return;
|
||||
}
|
||||
|
||||
@@ -300,7 +300,7 @@ class class_upload
|
||||
//-------------------------------------------------
|
||||
|
||||
$this->file_extension = $this->_get_file_extension( $FILE_NAME );
|
||||
|
||||
|
||||
if ( ! $this->file_extension )
|
||||
{
|
||||
$this->error_no = 2;
|
||||
@@ -334,7 +334,7 @@ class class_upload
|
||||
//-------------------------------------------------
|
||||
|
||||
$FILE_NAME = preg_replace( "/[^\w\.]/", "_", $FILE_NAME );
|
||||
|
||||
|
||||
$this->original_file_name = $FILE_NAME;
|
||||
|
||||
//-------------------------------------------------
|
||||
@@ -355,12 +355,17 @@ class class_upload
|
||||
// Make safe?
|
||||
//-------------------------------------------------
|
||||
|
||||
$renamed = 0;
|
||||
|
||||
if ( $this->make_script_safe )
|
||||
{
|
||||
if ( preg_match( "/\.(cgi|pl|js|asp|php|html|htm|jsp|jar)$/i", $FILE_NAME ) )
|
||||
if ( preg_match( "/\.(cgi|pl|js|asp|php|html|htm|jsp|jar)(\.|$)/i", $FILE_NAME ) )
|
||||
{
|
||||
$FILE_TYPE = 'text/plain';
|
||||
$this->file_extension = 'txt';
|
||||
$this->parsed_file_name = preg_replace( "/\.(cgi|pl|js|asp|php|html|htm|jsp|jar)(\.|$)/i", "$2", $this->parsed_file_name );
|
||||
|
||||
$renamed = 1;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -370,12 +375,12 @@ class class_upload
|
||||
|
||||
if ( is_array( $this->image_ext ) and count( $this->image_ext ) )
|
||||
{
|
||||
if ( in_array( $this->file_extension, $this->image_ext ) )
|
||||
if ( in_array( $this->real_file_extension, $this->image_ext ) )
|
||||
{
|
||||
$this->is_image = 1;
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
//-------------------------------------------------
|
||||
// Add on the extension...
|
||||
//-------------------------------------------------
|
||||
@@ -405,7 +410,17 @@ class class_upload
|
||||
{
|
||||
@chmod( $this->saved_upload_name, 0777 );
|
||||
}
|
||||
|
||||
|
||||
if( !$renamed )
|
||||
{
|
||||
$this->check_xss_infile();
|
||||
|
||||
if( $this->error_no )
|
||||
{
|
||||
return;
|
||||
}
|
||||
}
|
||||
|
||||
//-------------------------------------------------
|
||||
// Is it an image?
|
||||
//-------------------------------------------------
|
||||
@@ -453,12 +468,50 @@ class class_upload
|
||||
if( filesize($this->saved_upload_name) != $_FILES[ $this->upload_form_field ]['size'] )
|
||||
{
|
||||
@unlink( $this->saved_upload_name );
|
||||
|
||||
|
||||
$this->error_no = 1;
|
||||
return;
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
/*-------------------------------------------------------------------------*/
|
||||
// INTERNAL: Check for XSS inside file
|
||||
/*-------------------------------------------------------------------------*/
|
||||
|
||||
/**
|
||||
* Checks for XSS inside file. If found, sets error_no to 5 and returns
|
||||
*
|
||||
* @param void
|
||||
*/
|
||||
|
||||
function check_xss_infile()
|
||||
{
|
||||
// HTML added inside an inline file is not good in IE...
|
||||
|
||||
$fh = fopen( $this->saved_upload_name, 'rb' );
|
||||
|
||||
$file_check = fread( $fh, 512 );
|
||||
|
||||
fclose( $fh );
|
||||
|
||||
if( !$file_check )
|
||||
{
|
||||
@unlink( $this->saved_upload_name );
|
||||
$this->error_no = 5;
|
||||
return;
|
||||
}
|
||||
|
||||
# Thanks to Nicolas Grekas from comments at www.splitbrain.org for helping to identify all vulnerable HTML tags
|
||||
|
||||
else if( preg_match( "#<script|<html|<head|<title|<body|<pre|<table|<a\s+href|<img|<plaintext|<cross\-domain\-policy#si", $file_check ) )
|
||||
{
|
||||
@unlink( $this->saved_upload_name );
|
||||
$this->error_no = 5;
|
||||
return;
|
||||
}
|
||||
}
|
||||
|
||||
/*-------------------------------------------------------------------------*/
|
||||
// INTERNAL: Get file extension
|
||||
/*-------------------------------------------------------------------------*/
|
||||
|
||||
Reference in new issue
Block a user