Version 3.2.3
This commit is contained in:
1 parent
ae5c01cc78
commit
78706903a2
2641 files changed
+228363
-201264
No files matched your search
@@ -3,19 +3,19 @@
|
||||
/**
|
||||
* <pre>
|
||||
* Invision Power Services
|
||||
* IP.Board v3.1.4
|
||||
* IP.Board v3.2.3
|
||||
* Image Handler: create thumbnails, apply watermarks and copyright tests, save or display final image
|
||||
* Last Updated: $Date: 2010-11-10 11:27:28 -0500 (Wed, 10 Nov 2010) $
|
||||
* Last Updated: $Date: 2011-09-08 11:58:29 -0400 (Thu, 08 Sep 2011) $
|
||||
* </pre>
|
||||
*
|
||||
* @author $Author: mmecham $
|
||||
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/community/board/license.html
|
||||
* @license This is NULLED!
|
||||
* @package IP.Board
|
||||
* @subpackage Kernel
|
||||
* @link http://www.invisionpower.com
|
||||
* @link http://hatynka.in
|
||||
* @since Monday 5th May 2008 14:00
|
||||
* @version $Revision: 485 $
|
||||
* @version $Revision: 9467 $
|
||||
*
|
||||
* GD Example
|
||||
* <code>
|
||||
@@ -54,12 +54,12 @@ class ips_kernel_image
|
||||
{
|
||||
if ( $load == 'im' )
|
||||
{
|
||||
require_once( IPS_KERNEL_PATH . 'classImageImagemagick.php' );
|
||||
require_once( IPS_KERNEL_PATH . 'classImageImagemagick.php' );/*noLibHook*/
|
||||
$img = new classImageImagemagick();
|
||||
}
|
||||
else
|
||||
{
|
||||
require_once( IPS_KERNEL_PATH . 'classImageGd.php' );
|
||||
require_once( IPS_KERNEL_PATH . 'classImageGd.php' );/*noLibHook*/
|
||||
$img = new classImageGd();
|
||||
}
|
||||
|
||||
@@ -109,7 +109,7 @@ interface interfaceImage
|
||||
/**
|
||||
* Print image to screen
|
||||
*
|
||||
* @return void Image printed and script exits
|
||||
* @return @e void Image printed and script exits
|
||||
*/
|
||||
public function displayImage();
|
||||
|
||||
@@ -226,7 +226,7 @@ abstract class classImage
|
||||
* Image handler desctructor
|
||||
*
|
||||
* @access public
|
||||
* @return void
|
||||
* @return @e void
|
||||
*/
|
||||
public function __destruct()
|
||||
{
|
||||
@@ -270,6 +270,77 @@ abstract class classImage
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Checks to see if an uploaded image truly is an image
|
||||
* @param string $imagePath
|
||||
* @return mixed (false, is not image, array with data)
|
||||
*/
|
||||
public function extractImageData( $imagePath )
|
||||
{
|
||||
$fileExt = IPSText::getFileExtension( $imagePath );
|
||||
|
||||
$img_attributes = @getimagesize( $imagePath );
|
||||
|
||||
if ( ! is_array( $img_attributes ) or ! count( $img_attributes ) )
|
||||
{
|
||||
return false;
|
||||
}
|
||||
else if ( ! $img_attributes[2] )
|
||||
{
|
||||
return false;
|
||||
}
|
||||
else if ( $img_attributes[2] == 1 AND ( $fileExt == 'jpg' OR $fileExt == 'jpeg' ) )
|
||||
{
|
||||
return false;
|
||||
}
|
||||
|
||||
$return = array( 'width' => $img_attributes[0],
|
||||
'height' => $img_attributes[1],
|
||||
'fileType' => '' );
|
||||
|
||||
switch( $img_attributes[2] )
|
||||
{
|
||||
case 1:
|
||||
$return['fileType'] = 'gif';
|
||||
break;
|
||||
case 2:
|
||||
$return['fileType'] = 'jpg';
|
||||
break;
|
||||
case 3:
|
||||
$return['fileType'] = 'png';
|
||||
break;
|
||||
}
|
||||
|
||||
return $return;
|
||||
}
|
||||
|
||||
/**
|
||||
* Checks for XSS inside file. If found, deletes file, sets error_no to 5 and returns
|
||||
*
|
||||
* @return @e void
|
||||
*/
|
||||
public function hasXssInfile( $fileName )
|
||||
{
|
||||
// HTML added inside an inline file is not good in IE...
|
||||
$fh = fopen( $fileName, 'rb' );
|
||||
|
||||
$file_check = fread( $fh, 512 );
|
||||
|
||||
fclose( $fh );
|
||||
|
||||
if ( ! $file_check )
|
||||
{
|
||||
return true;
|
||||
}
|
||||
# Thanks to Nicolas Grekas from comments at www.splitbrain.org for helping to identify all vulnerable HTML tags
|
||||
else if ( preg_match( '#<script|<html|<head|<title|<body|<pre|<table|<a\s+href|<img|<plaintext|<cross\-domain\-policy#si', $file_check ) )
|
||||
{
|
||||
return true;
|
||||
}
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get new dimensions for resizing
|
||||
*
|
||||
|
||||
Reference in new issue
Block a user