Version 2.3.6

This commit is contained in:
Neo committed 2025-12-19 00:26:08 -08:00
1 parent a3bb603c96
commit 19b38c7c74
764 files changed
+143731 -118164

No files matched your search

+71 -18
View File
@@ -2,22 +2,14 @@
/*
+--------------------------------------------------------------------------
| Invision Power Board 2.2.2
| Invision Power Board
| =============================================
| by Matthew Mecham
| (c) 2001 - 2006 Invision Power Services, Inc.
| http://www.invisionpower.com
| =============================================
| Web: http://www.invisionboard.com
| http://www.ibresource.ru/products/invisionpowerboard/
| Time: Monday 05th of March 2007 10:10:55 PM
| Release: e3790216629e5a2aaf37070b32237f06
| Licence Info: http://www.invisionboard.com/?license
| http://www.ibresource.ru/license
+---------------------------------------------------------------------------
| INVISION POWER BOARD ÍÅ ßÂËßÅÒÑß ÁÅÑÏËÀÒÍÛÌ ÏÐÎÃÐÀÌÌÍÛÌ ÎÁÅÑÏÅ×ÅÍÈÅÌ!
| Ïðàâà íà ÏÎ ïðèíàäëåæàò Invision Power Services
| Ïðàâà íà ïåðåâîä IBResource (http://www.ibresource.ru)
+---------------------------------------------------------------------------
| > $Date: 2005-10-10 14:03:20 +0100 (Mon, 10 Oct 2005) $
| > $Revision: 22 $
@@ -256,7 +248,7 @@ class class_upload
$FILE_NAME = isset($_FILES[ $this->upload_form_field ]['name']) ? $_FILES[ $this->upload_form_field ]['name'] : '';
$FILE_SIZE = isset($_FILES[ $this->upload_form_field ]['size']) ? $_FILES[ $this->upload_form_field ]['size'] : '';
$FILE_TYPE = isset($_FILES[ $this->upload_form_field ]['type']) ? $_FILES[ $this->upload_form_field ]['type'] : '';
//-------------------------------------------------
// Naughty Opera adds the filename on the end of the
// mime type - we don't want this.
@@ -275,7 +267,15 @@ class class_upload
or !$_FILES[ $this->upload_form_field ]['size']
or ($_FILES[ $this->upload_form_field ]['name'] == "none") )
{
$this->error_no = 1;
if( $_FILES[ $this->upload_form_field ]['error'] == 2 )
{
$this->error_no = 3;
}
else
{
$this->error_no = 1;
}
return;
}
@@ -300,7 +300,7 @@ class class_upload
//-------------------------------------------------
$this->file_extension = $this->_get_file_extension( $FILE_NAME );
if ( ! $this->file_extension )
{
$this->error_no = 2;
@@ -334,7 +334,7 @@ class class_upload
//-------------------------------------------------
$FILE_NAME = preg_replace( "/[^\w\.]/", "_", $FILE_NAME );
$this->original_file_name = $FILE_NAME;
//-------------------------------------------------
@@ -355,12 +355,17 @@ class class_upload
// Make safe?
//-------------------------------------------------
$renamed = 0;
if ( $this->make_script_safe )
{
if ( preg_match( "/\.(cgi|pl|js|asp|php|html|htm|jsp|jar)$/i", $FILE_NAME ) )
if ( preg_match( "/\.(cgi|pl|js|asp|php|html|htm|jsp|jar)(\.|$)/i", $FILE_NAME ) )
{
$FILE_TYPE = 'text/plain';
$this->file_extension = 'txt';
$this->parsed_file_name = preg_replace( "/\.(cgi|pl|js|asp|php|html|htm|jsp|jar)(\.|$)/i", "$2", $this->parsed_file_name );
$renamed = 1;
}
}
@@ -370,12 +375,12 @@ class class_upload
if ( is_array( $this->image_ext ) and count( $this->image_ext ) )
{
if ( in_array( $this->file_extension, $this->image_ext ) )
if ( in_array( $this->real_file_extension, $this->image_ext ) )
{
$this->is_image = 1;
}
}
//-------------------------------------------------
// Add on the extension...
//-------------------------------------------------
@@ -405,7 +410,17 @@ class class_upload
{
@chmod( $this->saved_upload_name, 0777 );
}
if( !$renamed )
{
$this->check_xss_infile();
if( $this->error_no )
{
return;
}
}
//-------------------------------------------------
// Is it an image?
//-------------------------------------------------
@@ -453,12 +468,50 @@ class class_upload
if( filesize($this->saved_upload_name) != $_FILES[ $this->upload_form_field ]['size'] )
{
@unlink( $this->saved_upload_name );
$this->error_no = 1;
return;
}
}
/*-------------------------------------------------------------------------*/
// INTERNAL: Check for XSS inside file
/*-------------------------------------------------------------------------*/
/**
* Checks for XSS inside file. If found, sets error_no to 5 and returns
*
* @param void
*/
function check_xss_infile()
{
// HTML added inside an inline file is not good in IE...
$fh = fopen( $this->saved_upload_name, 'rb' );
$file_check = fread( $fh, 512 );
fclose( $fh );
if( !$file_check )
{
@unlink( $this->saved_upload_name );
$this->error_no = 5;
return;
}
# Thanks to Nicolas Grekas from comments at www.splitbrain.org for helping to identify all vulnerable HTML tags
else if( preg_match( "#<script|<html|<head|<title|<body|<pre|<table|<a\s+href|<img|<plaintext|<cross\-domain\-policy#si", $file_check ) )
{
@unlink( $this->saved_upload_name );
$this->error_no = 5;
return;
}
}
/*-------------------------------------------------------------------------*/
// INTERNAL: Get file extension
/*-------------------------------------------------------------------------*/