Version 2.3.6

This commit is contained in:
Neo committed 2025-12-19 00:26:08 -08:00
1 parent a3bb603c96
commit 19b38c7c74
764 files changed
+143731 -118164

No files matched your search

File diff suppressed because it is too large. Load diff
@@ -2,27 +2,17 @@
/*
+--------------------------------------------------------------------------
| Invision Power Board 2.2.2
| Invision Power Board
| =============================================
| by Matthew Mecham
| (c) 2001 - 2006 Invision Power Services, Inc.
| http://www.invisionpower.com
| =============================================
| Web: http://www.invisionboard.com
| http://www.ibresource.ru/products/invisionpowerboard/
| Time: Monday 05th of March 2007 10:10:54 PM
| Release: e3790216629e5a2aaf37070b32237f06
| Licence Info: http://www.invisionboard.com/?license
| http://www.ibresource.ru/license
+---------------------------------------------------------------------------
| INVISION POWER BOARD IS NOT FREE / OPEN SOURCE!
+---------------------------------------------------------------------------
| INVISION POWER BOARD ÍÅ ßÂËßÅÒÑß ÁÅÑÏËÀÒÍÛÌ ÏÐÎÃÐÀÌÌÍÛÌ ÎÁÅÑÏÅ×ÅÍÈÅÌ!
| Ïðàâà íà ÏÎ ïðèíàäëåæàò Invision Power Services
| Ïðàâà íà ïåðåâîä IBResource (http://www.ibresource.ru)
+---------------------------------------------------------------------------
| > $Date: 2006-11-29 16:22:46 -0600 (Wed, 29 Nov 2006) $
| > $Revision: 745 $
| > $Date: 2008-03-28 18:08:02 -0400 (Fri, 28 Mar 2008) $
| > $Revision: 1232 $
| > $Author: bfarber $
+---------------------------------------------------------------------------
|
@@ -97,8 +87,8 @@
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Íåêîððåêòíûé àäðåñ</h1>Âû íå èìååòå äîñòóïà ê ýòîìó ôàéëó íàïðÿìóþ. Åñëè âû íåäàâíî îáíîâëÿëè ôîðóì, âû äîëæíû îáíîâèòü âñå ñîîòâåòñòâóþùèå ôàéëû.";
exit();
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
class class_bbcode_core
@@ -398,6 +388,13 @@ class class_bbcode_core
*/
function clean_ipb_html( $t="" )
{
$t = $this->post_db_unparse_bbcode( $t );
//-----------------------------------------
// IE handles RTE BR tags differently
//-----------------------------------------
$t = str_replace( "<BR>", "<br />", $t );
//-----------------------------------------
// left, right, center
//-----------------------------------------
@@ -479,6 +476,24 @@ class class_bbcode_core
$t = preg_replace( "#<\{.+?\}>#", "", $t );
//-----------------------------------------
// Opening style attributes
//-----------------------------------------
$t = preg_replace( "#<!--sizeo:(.+?)-->(.+?)<!--/sizeo-->#" , '<font size="\\1">' , $t );
$t = preg_replace( "#<!--coloro:(.+?)-->(.+?)<!--/coloro-->#" , '<font color="\\1">' , $t );
$t = preg_replace( "#<!--fonto:(.+?)-->(.+?)<!--/fonto-->#" , '<font face="\\1">' , $t );
$t = preg_replace( "#<!--backgroundo:(.+?)-->(.+?)<!--/backgroundo-->#" , '<font background="\\1">' , $t );
//-----------------------------------------
// Closing style attributes
//-----------------------------------------
$t = preg_replace( "#<!--sizec-->(.+?)<!--/sizec-->#" , "</font>" , $t );
$t = preg_replace( "#<!--colorc-->(.+?)<!--/colorc-->#" , "</font>" , $t );
$t = preg_replace( "#<!--fontc-->(.+?)<!--/fontc-->#" , "</font>" , $t );
$t = preg_replace( "#<!--backgroundc-->(.+?)<!--/backgroundc-->#", "</font>" , $t );
//-----------------------------------------
// Clean up code tags
//-----------------------------------------
@@ -503,7 +518,7 @@ class class_bbcode_core
//-----------------------------------------
// INIT
//-----------------------------------------
$txt = $matches[1];
//-----------------------------------------
@@ -532,7 +547,7 @@ class class_bbcode_core
*/
function strip_quote_tags( $txt="" )
{
return preg_replace( "#\[QUOTE(=.+?,.+?)?\].+?\[/QUOTE\]#is", "", $txt );
return preg_replace( "#\[QUOTE(=.+?,.+?)?\].+?\[/QUOTE\]#ism", "", $txt );
}
/*-------------------------------------------------------------------------*/
@@ -545,17 +560,28 @@ class class_bbcode_core
* @param string Raw text
* @return string Converted text
*/
function strip_all_tags( $txt="" )
function strip_all_tags( $txt="", $pre_edit_parse=1 )
{
$txt = $this->strip_quote_tags( $this->pre_edit_parse( $txt ) );
while( preg_match( "#\[.+?\](.+?)\[/.+?\]#is", $txt ) )
if( $pre_edit_parse )
{
$txt = preg_replace( "#\[.+?\](.+?)\[/.+?\]#is", "\\1", $txt );
$txt = $this->pre_edit_parse( $txt );
}
$txt = $this->strip_quote_tags( $txt );
$txt = preg_replace( "#\[(.+?)\](.+?)\[/\\1\]#is", "\\2", $txt );
$txt = preg_replace( "#\[url\s*=\s*(?:\&quot\;|\")\s*(.*?)\s*(?:\&quot\;|\")\s*\](.*?)\[\/url\]#is", "\\2", $txt );
$txt = preg_replace( "#\[url\s*=\s*(.*?)\s*\](.*?)\[\/url\]#is" , "\\2", $txt );
$txt = preg_replace( "#\[email\s*=\s*\&quot\;([\.\w\-]+\@[\.\w\-]+\.[\.\w\-]+)\s*\&quot\;\s*\](.*?)\[\/email\]#i" , "\\2", $txt );
$txt = preg_replace( "#\[email\s*=\s*([\.\w\-]+\@[\.\w\-]+\.[\w\-]+)\s*\](.*?)\[\/email\]#i" , "\\2", $txt );
$txt = preg_replace( "#\[background=([^\]]+)\](.+?)\[/background\]#is", "\\2", $txt );
$txt = preg_replace( "#\[size=([^\]]+)\](.+?)\[/size\]#is" , "\\2", $txt );
$txt = preg_replace( "#\[font=([^\]]+)\](.+?)\[/font\]#is" , "\\2", $txt );
$txt = preg_replace( "#\[color=([^\]]+)\](.+?)\[/color\]#is" , "\\2", $txt );
$txt = preg_replace( "#\[attach.+?\]#is" , "" , $txt );
return $txt;
}
@@ -725,71 +751,76 @@ class class_bbcode_core
if ( $row['bbcode_useoption'] )
{
while (preg_match_all( "#(\[".$preg_tag."=(?:&quot;|&\#39;|\")?(.+?)(?:&quot;|&\#39;|\")?\])((?R)|.*?)(\[/".$preg_tag."\])#si", $t, $match ))
// If we don't check &quot; or &#39;, topic tag dies when it's in format of [topic="number"]
while (preg_match_all( "#(\[".$preg_tag."=(?:\"|&quot;|'|&\#39;)?(.+?)(?:\"|'|&quot;|&\#39;)?\])((?R)|.*?)(\[/".$preg_tag."\])#si", $t, $match ))
{
for ( $i = 0; $i < count($match[0]); $i++)
{
//-----------------------------------------
// Does the option tag come first?
//-----------------------------------------
$_option = 2;
$_content = 3;
if ( $row['bbcode_switch_option'] )
for ( $i = 0; $i < count($match[0]); $i++)
{
$_option = 3;
$_content = 2;
}
# XSS Check: Bug ID: 980
if ( $row['bbcode_tag'] == 'post' OR $row['bbcode_tag'] == 'topic' OR $row['bbcode_tag'] == 'snapback' )
{
$match[ $_option ][$i] = intval( $match[ $_option ][$i] );
}
# Recurse?
if ( preg_match( "#\[.+?\]#s", $match[ $_content ][$i] ) )
{
$match[ $_content ][$i] = $this->post_db_parse_bbcode( $match[ $_content ][$i] );
}
//-----------------------------------------
// Does the option tag come first?
//-----------------------------------------
$tmp = $row['bbcode_replace'];
$tmp = str_replace( '{option}' , $match[ $_option ][$i], $tmp );
$tmp = str_replace( '{content}', $match[ $_content ][$i], $tmp );
$t = str_replace( $match[0][$i], $tmp, $t );
$_option = 2;
$_content = 3;
if ( $row['bbcode_switch_option'] )
{
$_option = 3;
$_content = 2;
}
# XSS Check: Bug ID: 980
if ( $row['bbcode_tag'] == 'post' OR $row['bbcode_tag'] == 'topic' OR $row['bbcode_tag'] == 'snapback' )
{
$match[ $_option ][$i] = intval( $match[ $_option ][$i] );
}
# Recurse?
if ( preg_match( "#\[.+?\]#s", $match[ $_content ][$i] ) )
{
$match[ $_content ][$i] = $this->post_db_parse_bbcode( $match[ $_content ][$i] );
}
//$match[ $_content ][$i] = preg_replace( '#(style)=#is', "$1&#61;", $match[ $_content ][$i] );
//$match[ $_option ][$i] = preg_replace( '#(style)=#is', "$1&#61;", $match[ $_option ][$i] );
$tmp = $row['bbcode_replace'];
$tmp = str_replace( '{option}' , $this->ipsclass->xss_html_clean( $match[ $_option ][$i] ), $tmp );
$tmp = str_replace( '{content}', $this->ipsclass->xss_html_clean( $match[ $_content ][$i] ), $tmp );
$t = str_replace( $match[0][$i], $tmp, $t );
}
}
}
}
else
{
# Tricky.. match anything that's not a closing tag, or nothing
while (preg_match_all( "#(\[$preg_tag\])((?R)|.*?)(\[/$preg_tag\])#si", $t, $match ))
{
for ( $i = 0; $i < count($match[0]); $i++)
{
# Recurse?
if ( preg_match( "#\[.+?\]#s", $match[2][$i] ) )
for ( $i = 0; $i < count($match[0]); $i++)
{
$match[2][$i] = $this->post_db_parse_bbcode( $match[2][$i] );
# Recurse?
if ( preg_match( "#\[.+?\]#s", $match[2][$i] ) )
{
$match[2][$i] = $this->post_db_parse_bbcode( $match[2][$i] );
}
# XSS Check: Bug ID: 980
if ( $row['bbcode_tag'] == 'snapback' )
{
$match[2][$i] = intval( $match[2][$i] );
}
$tmp = $row['bbcode_replace'];
$tmp = str_replace( '{content}', $match[2][$i], $tmp );
$t = str_replace( $match[0][$i], $tmp, $t );
}
# XSS Check: Bug ID: 980
if ( $row['bbcode_tag'] == 'snapback' )
{
$match[2][$i] = intval( $match[2][$i] );
}
$tmp = $row['bbcode_replace'];
$tmp = str_replace( '{content}', $match[2][$i], $tmp );
$t = str_replace( $match[0][$i], $tmp, $t );
}
}
}
}
}
//-----------------------------------------
// Snapback used?
//-----------------------------------------
@@ -802,6 +833,126 @@ class class_bbcode_core
return $t;
}
/*-------------------------------------------------------------------------*/
// Post DB UNparse BBCode
/*-------------------------------------------------------------------------*/
/**
* Pre-edit unparse custom BBCode
*
* @param string Converted text
* @return string Raw text
*/
function post_db_unparse_bbcode($t="")
{
//-----------------------------------------
// INIT
//-----------------------------------------
$snapback = 0;
//-----------------------------------------
// Check...
//-----------------------------------------
if ( is_array( $this->ipsclass->cache['bbcode'] ) and count( $this->ipsclass->cache['bbcode'] ) )
{
foreach( $this->ipsclass->cache['bbcode'] as $row )
{
if ( strtolower($row['bbcode_tag']) == 'snapback' )
{
$snapback = 1;
}
$preg_tag = preg_quote( $row['bbcode_replace'], '#' );
//NK: only return the first match
$preg_tag = preg_replace( '/\\\{option\\\}/', '(.*?)', $preg_tag, 1 );
$preg_tag = preg_replace( '/\\\{content\\\}/', '(.*?)', $preg_tag, 1 );
$preg_tag = str_replace( '\{option\}', '.*?', $preg_tag );
$preg_tag = str_replace( '\{content\}', '.*?', $preg_tag );
/*$preg_tag = str_replace( '\{option\}', '.(*?)', $preg_tag );
$preg_tag = str_replace( '\{content\}', '(.*?)', $preg_tag );*/
// Bug 5658 - </span> tags in custom bbcode don't play nice with inbuilt bbcode
$preg_tag = str_replace( "\</span\>", "\</span\>(?!\<\!--/sizec|\<\!--/colorc|\<\!--/fontc|\<\!--/backgroundc)", $preg_tag );
//-----------------------------------------
// Slightly slower
//-----------------------------------------
while ( preg_match_all( "#".$preg_tag."#si", $t, $match ) )
{
for ( $i = 0; $i < count($match[0]); $i++)
{
//-----------------------------------------
// Does the option tag come first?
//-----------------------------------------
$_option = 1;
$_content = 2;
if ( $row['bbcode_switch_option'] )
{
$_option = 2;
$_content = 1;
}
else if( count( $match ) == 2 )
{
$_content = 1;
}
# XSS Check: Bug ID: 980
if ( $row['bbcode_tag'] == 'post' OR $row['bbcode_tag'] == 'topic' OR $row['bbcode_tag'] == 'snapback' )
{
$match[ $_option ][$i] = intval( $match[ $_option ][$i] );
}
# Recurse?
if ( preg_match( "#".$preg_tag."#si", $match[ $_content ][$i] ) )
{
$match[ $_content ][$i] = $this->post_db_parse_bbcode( $match[ $_content ][$i] );
}
$tmp = '[' . $row['bbcode_tag'];
if( $row['bbcode_useoption'] )
{
if( $row['bbcode_switch_option'] )
{
$tmp .= '={content}]{option}[/' . $row['bbcode_tag'] . ']';
}
else
{
$tmp .= '={option}]{content}[/' . $row['bbcode_tag'] . ']';
}
}
else
{
$tmp .= ']{content}[/' . $row['bbcode_tag'] . ']';
}
$tmp = str_replace( '{option}' , $match[ $_option ][$i], $tmp );
$tmp = str_replace( '{content}', $match[ $_content ][$i], $tmp );
$t = str_replace( $match[0][$i], $tmp, $t );
}
}
}
}
//-----------------------------------------
// Snapback used?
//-----------------------------------------
if ( ! $snapback )
{
$t = preg_replace( "#\<a href=\'index\.php\?act=findpost&amp;pid=([0-9]+?)\'\>\<\{POST_SNAPBACK\}\>\<\/a\>#is", "[snapback]\\1[/snapback]", $t );
}
return $t;
}
//-----------------------------------------
// Word wrap, wraps 'da word innit
//-----------------------------------------
@@ -823,9 +974,10 @@ class class_bbcode_core
{
return $t;
}
#var_dump( $t );
$t = preg_replace("#([^\s<>'\"/\\-\?&\n\r\%]{".$chrs."})([^\s<>'\"/\\-\?&\n\r\%]{1})#i", "\\1".$replace."\\2" ,$t);
$t = preg_replace("#([^\s<>'\"/\\-\?&\n\r\%]{".$chrs."})#i", "\\1".$replace ,$t);
#print $chrs.' '.var_dump($replace).var_dump( $t );exit;
return $t;
}
@@ -1061,7 +1213,7 @@ class class_bbcode_core
$html = preg_replace( "/^<br>/" , "", $html );
$html = preg_replace( "#^<br />#", "", $html );
$html = preg_replace( "/^\s+/" , "", $html );
$html = preg_replace( "#&lt;([^&<>]+)&gt;#" , "&lt;<span style='color:blue'>\\1</span>&gt;" , $html ); //Matches <tag>
$html = preg_replace( "#&\#60;([a-zA-Z0-9]+)([&gt;|\s])#" , "&#60;<span style='color:blue'>\\1</span>\\2" , $html ); //Matches <script[ |>]
$html = preg_replace( "#&lt;([^&<>]+)\s#" , "&lt;<span style='color:blue'>\\1</span> " , $html ); //Matches <tag
@@ -1144,7 +1296,7 @@ class class_bbcode_core
//-----------------------------------------
// We don't want to trim indentations on the first line
//-----------------------------------------
$txt = rtrim( $matches[1] );
$txt = preg_replace( "#^(\n+)(.+?)$#s", "\\2", $txt );
@@ -1178,12 +1330,12 @@ class class_bbcode_core
//-----------------------------------------
// Ensure that spacing is preserved
//-----------------------------------------
$txt = preg_replace( "#\t#" , "&nbsp;&nbsp;&nbsp;&nbsp;", $txt );
$txt = preg_replace( "#\s{2}#", "&nbsp;&nbsp;" , $txt );
$html = $this->wrap_style( 'code' );
return "<!--c1-->{$html['START']}<!--ec1-->$txt<!--c2-->{$html['END']}<!--ec2-->";
}
@@ -1219,7 +1371,7 @@ class class_bbcode_core
//-----------------------------------------
// Make sure we've not overriden the set image # limit
//-----------------------------------------
if ( $this->ipsclass->vars['max_images'] )
{
if ($this->image_count > $this->ipsclass->vars['max_images'])
@@ -1243,8 +1395,9 @@ class class_bbcode_core
if ( $this->ipsclass->vars['allow_dynamic_img'] != 1 )
{
if ( preg_match( "/[?&;%<\[\]]/", $url) )
if ( preg_match( "/[?&<]/", $url) )
{
//var_dump($url);
$this->error = 'no_dynamic';
return $default;
}
@@ -1256,6 +1409,28 @@ class class_bbcode_core
}
}
//-----------------------------------------
// Is there another bbcode + js?
// Block XSS attempt
//-----------------------------------------
$bbcodes = array( 'b', 'i', 'u', 's', 'center', 'left', 'right', 'url', 'email', 'code', 'quote', 'sql', 'html',
'indent', 'list', 'flash', 'sub', 'sup', 'background', 'color', 'size', 'font' );
if ( is_array( $this->ipsclass->cache['bbcode'] ) and count( $this->ipsclass->cache['bbcode'] ) )
{
foreach( $this->ipsclass->cache['bbcode'] as $row )
{
$bbcodes[] = preg_quote( $row['bbcode_tag'], '#' );
}
}
if ( preg_match( "#\[(" . implode( '|', $bbcodes ) . ")(.*?)\]#is", $url ) )
{
$this->error = 'domain_not_allowed';
return $default;
}
//-----------------------------------------
// Check...
//-----------------------------------------
@@ -1265,6 +1440,42 @@ class class_bbcode_core
return '';
}
//-----------------------------------------
// Don't let emos in URL..
//-----------------------------------------
if ( $this->parse_smilies )
{
if ( count( $this->ipsclass->cache['emoticons'] ) > 0 )
{
foreach( $this->ipsclass->cache['emoticons'] as $row)
{
$code = $row['typed'];
$code = str_replace( '<', '&lt;', str_replace( '>', '&gt;', $code ) );
if( strpos( $url, $code ) )
{
$new = '';
for( $i=0; $i<strlen($code); $i++ )
{
//print dechex(ord($code{$i})).'<Br>';
$new .= '%' . dechex(ord($code{$i}));
}
$url = str_replace( $code, $new, $url );
}
}
// Using the :/ smiley
$url = str_replace( 'http%3a%2f', 'http:/', $url );
$url = str_replace( 'https%3a%2f', 'https:/', $url );
}
}
$url = htmlspecialchars($url);
$url = str_replace( '&amp;amp;', '&amp;', $url );
//-----------------------------------------
// Is the img extension allowed to be posted?
//-----------------------------------------
@@ -1309,6 +1520,11 @@ class class_bbcode_core
foreach( $list_values as $my_url )
{
if( !trim($my_url) )
{
continue;
}
$my_url = preg_quote( $my_url, '/' );
$my_url = str_replace( "\*", "(.*?)", $my_url );
@@ -1355,9 +1571,9 @@ class class_bbcode_core
//-----------------------------------------
// Signature?
//-----------------------------------------
$_class = ( $this->parsing_signature ) ? 'linked-sig-image' : 'linked-image';
// If we add an alt tag - won't be able to delete image in RTE
return "<img src=\"$url\" border=\"0\" class=\"". $_class ."\" />";
}
@@ -1527,17 +1743,23 @@ class class_bbcode_core
//-----------------------------------------
// INIT
//-----------------------------------------
if ( count( $matches ) == 3 )
$types = array( 'a', 'A', 'i', 'I', '1' );
if ( in_array( $matches[2], $types ) )
{
$type = $matches[1];
$txt = $matches[2];
$fnl = $matches[1];
$type = $matches[2];
$txt = $matches[3];
$lnl = $matches[4];
}
else
{
$txt = $matches[1];
$fnl = $matches[1];
$txt = $matches[2];
$lnl = $matches[3];
}
if ( $txt == "" )
{
return;
@@ -1547,11 +1769,11 @@ class class_bbcode_core
if ( $type == "" )
{
return "<ul>".$this->regex_list_item($txt)."</ul>";
return $fnl . "<ul>".$this->regex_list_item($txt)."</ul>" . $lnl;
}
else
{
return "<ol type='$type'>".$this->regex_list_item($txt)."</ol>";
return $fnl . "<ol type='$type'>".$this->regex_list_item($txt)."</ol>" . $lnl;
}
}
@@ -1604,6 +1826,8 @@ class class_bbcode_core
return $txt;
}
//print $txt . "<hr>";
$txt = str_replace( chr(173).']', '&#93;', $txt );
// Trim quoted text
@@ -1612,6 +1836,9 @@ class class_bbcode_core
// Clean usernames with square brackets
$txt = preg_replace_callback( "#(name=(?:&\#39;|&quot;|'|\"))(.+?)(&\#39;|&quot;|'|\")#si", array( &$this, '_make_quote_safe' ), $txt );
// Clean usernames with quotes....
$txt = preg_replace_callback( "#name=(&\#39;|&quot;|'|\")(.+?)(\\1)\s?(post|date)=#si", array( &$this, '_make_quote_name_safe' ), $txt );
$this->quote_html = $this->wrap_style('quote');
$txt = preg_replace_callback( "#\[/quote\]#i" , array( &$this, 'regex_close_quote' ) , $txt );
@@ -1620,7 +1847,12 @@ class class_bbcode_core
$txt = preg_replace_callback( "#\[quote([^\]]+?)?\]#i" , array( &$this, 'regex_simple_quote_tag' ), $txt );
$txt = str_replace( "\n", "<br />", $txt );
# Final clean...
$txt = str_replace( "&#0039;", "&#39;", $txt );
//print htmlspecialchars( $txt ); exit();
if ( ($this->quote_open == $this->quote_closed) and ($this->quote_error == 0) )
{
return $txt;
@@ -1633,7 +1865,6 @@ class class_bbcode_core
}
}
/*-------------------------------------------------------------------------*/
// regex_trim_quote: Trims quoted text
/*-------------------------------------------------------------------------*/
@@ -1888,7 +2119,7 @@ class class_bbcode_core
//-----------------------------------------
// Send off to the correct function...
//-----------------------------------------
return $this->regex_build_url( array( 'st' => $matches[1],
'html' => $matches[2],
'show' => $matches[2],
@@ -1957,6 +2188,11 @@ class class_bbcode_core
foreach( $list_values as $my_url )
{
if( !trim($my_url) )
{
continue;
}
$my_url = preg_quote( $my_url, '/' );
$my_url = str_replace( "\*", "(.*?)", $my_url );
@@ -1984,6 +2220,60 @@ class class_bbcode_core
}
}
//-----------------------------------------
// Is there another bbcode + js?
// Block XSS attempt
//-----------------------------------------
$bbcodes = array( 'b', 'i', 'u', 's', 'center', 'left', 'right', 'url', 'email', 'code', 'quote', 'sql', 'html',
'indent', 'list', 'flash', 'sub', 'sup', 'background', 'color', 'size', 'font', 'img' );
if ( is_array( $this->ipsclass->cache['bbcode'] ) and count( $this->ipsclass->cache['bbcode'] ) )
{
foreach( $this->ipsclass->cache['bbcode'] as $row )
{
$bbcodes[] = preg_quote( $row['bbcode_tag'], '#' );
}
}
if ( preg_match( "#\[(" . implode( '|', $bbcodes ) . ")(.*?)\]#is", $url['html'] ) )
{
$this->error = 'domain_not_allowed';
return $url['html'];
}
//-----------------------------------------
// Don't let emos in URL..
//-----------------------------------------
if ( $this->parse_smilies )
{
if ( count( $this->ipsclass->cache['emoticons'] ) > 0 )
{
foreach( $this->ipsclass->cache['emoticons'] as $row)
{
$code = $row['typed'];
$code = str_replace( '<', '&lt;', str_replace( '>', '&gt;', $code ) );
if( strpos( $url['html'], $code ) )
{
$new = '';
for( $i=0; $i<strlen($code); $i++ )
{
//print dechex(ord($code{$i})).'<Br>';
$new .= '%' . dechex(ord($code{$i}));
}
$url['html'] = str_replace( $code, $new, $url['html'] );
}
}
// Using the :/ smiley
$url['html'] = str_replace( 'http%3a%2f', 'http:/', $url['html'] );
$url['html'] = str_replace( 'https%3a%2f', 'https:/', $url['html'] );
}
}
//-----------------------------------------
// Make sure the last character isn't punctuation..
@@ -2024,6 +2314,7 @@ class class_bbcode_core
// clean up the ampersands / brackets
//-----------------------------------------
$url['html'] = htmlspecialchars( $url['html'] );
$url['html'] = str_replace( "&amp;amp;", "&amp;", $url['html'] );
$url['html'] = str_replace( "[" , "%5b" , $url['html'] );
$url['html'] = str_replace( "]" , "%5d" , $url['html'] );
@@ -2202,7 +2493,7 @@ class class_bbcode_core
return $default;
}
return "<!--Flash $width+$height+$url--><OBJECT CLASSID='clsid:D27CDB6E-AE6D-11cf-96B8-444553540000' WIDTH=$width HEIGHT=$height><PARAM NAME=MOVIE VALUE=$url><PARAM NAME=PLAY VALUE=TRUE><PARAM NAME=LOOP VALUE=TRUE><PARAM NAME=QUALITY VALUE=HIGH><EMBED SRC=$url WIDTH=$width HEIGHT=$height PLAY=TRUE LOOP=TRUE QUALITY=HIGH></EMBED></OBJECT><!--End Flash-->";
return "<!--Flash $width+$height+$url--><OBJECT CLASSID='clsid:D27CDB6E-AE6D-11cf-96B8-444553540000' WIDTH='$width' HEIGHT='$height'><PARAM NAME='MOVIE' VALUE='$url'><PARAM NAME='PLAY' VALUE='TRUE'><PARAM NAME='LOOP' VALUE='TRUE'><PARAM NAME='QUALITY' VALUE='HIGH'><PARAM NAME='allowscriptaccess' VALUE='never'><EMBED AllowScriptAccess='never' SRC='$url' WIDTH='$width' HEIGHT='$height' PLAY='TRUE' LOOP='TRUE' QUALITY='HIGH'></EMBED></OBJECT><!--End Flash-->";
}
/*-------------------------------------------------------------------------*/
@@ -2222,7 +2513,7 @@ class class_bbcode_core
// INIT
//-----------------------------------------
$size = $matches[1];
$size = trim($matches[1]);
$text = $matches[2];
foreach( $this->font_sizes as $k => $v )
@@ -2410,6 +2701,28 @@ class class_bbcode_core
return $begin . $txt . $end;
}
/*-------------------------------------------------------------------------*/
// Fix up quoted usernames
/*-------------------------------------------------------------------------*/
/**
* Fix up quoted usernames
*
* @param array Quote data
* @return string Converted text
*/
function _make_quote_name_safe( $matches=array() )
{
$quote = $matches[1];
$name = $matches[2];
$next = $matches[4];
# Squeeze past the parser...
$name = str_replace( '&#39;', "&#0039;", $name );
return 'name=' . $quote . $name . $quote . ' ' . $next . '=';
}
/*-------------------------------------------------------------------------*/
// Parse new quotes
/*-------------------------------------------------------------------------*/
@@ -2,26 +2,16 @@
/*
+--------------------------------------------------------------------------
| Invision Power Board 2.2.2
| Invision Power Board
| =============================================
| by Matthew Mecham
| (c) 2001 - 2006 Invision Power Services, Inc.
| http://www.invisionpower.com
| =============================================
| Web: http://www.invisionboard.com
| http://www.ibresource.ru/products/invisionpowerboard/
| Time: Monday 05th of March 2007 10:10:54 PM
| Release: e3790216629e5a2aaf37070b32237f06
| Licence Info: http://www.invisionboard.com/?license
| http://www.ibresource.ru/license
+---------------------------------------------------------------------------
| INVISION POWER BOARD IS NOT FREE / OPEN SOURCE!
+---------------------------------------------------------------------------
| INVISION POWER BOARD ÍÅ ßÂËßÅÒÑß ÁÅÑÏËÀÒÍÛÌ ÏÐÎÃÐÀÌÌÍÛÌ ÎÁÅÑÏÅ×ÅÍÈÅÌ!
| Ïðàâà íà ÏÎ ïðèíàäëåæàò Invision Power Services
| Ïðàâà íà ïåðåâîä IBResource (http://www.ibresource.ru)
+---------------------------------------------------------------------------
| > $Date: 2006-09-22 05:28:54 -0500 (Fri, 22 Sep 2006) $
| > $Date: 2006-09-22 06:28:54 -0400 (Fri, 22 Sep 2006) $
| > $Revision: 567 $
| > $Author: matt $
+---------------------------------------------------------------------------
@@ -63,8 +53,8 @@
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Íåêîððåêòíûé àäðåñ</h1>Âû íå èìååòå äîñòóïà ê ýòîìó ôàéëó íàïðÿìóþ. Åñëè âû íåäàâíî îáíîâëÿëè ôîðóì, âû äîëæíû îáíîâèòü âñå ñîîòâåòñòâóþùèå ôàéëû.";
exit();
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
class class_bbcode extends class_bbcode_core
+1 -10
View File
@@ -1,10 +1 @@
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=windows-1251" />
<meta name="author" content="Êîìïàíèÿ IBResource è Invision Power Services Inc.">
<title>Îøèáêà ðóññêîé âåðñèè Invision Power Board</title>
</head><body>
<h1>Îøèáêà <a href="http://www.ibresource.ru/">ðóññêîé âåðñèè Invision Power Board</a></h1>
<font size="4">Âû ïîïàëè íà íåñóùåñòâóþùóþ ñòðàíèöó!<br>Ïîæàëóéñòà íàæìèòå íà êíîïî÷êó &laquo;<b>Íàçàä</b>&raquo; â&nbsp;âàøåì áðàóçåðå äëÿ âîçâðàùåíèÿ íà ïðåäûäóùóþ ñòðàíèöó.</font>
</body>
</html>
<html>␍<head><title>Invision Power Board - Bulletin Board System</title></head>␍<body>␍<h1>403: Invision Power Board -> Forbidden</h1>␍<hr>␍You have reached this Page in error, please use␍your back button to return to Invision Board.␍<hr>␍<a href="http://anonym.to/http://www.invisionboard.com/">Invision Power Board</a>␍</body>␍</html>␍