Version 3.2.3

This commit is contained in:
Neo committed 2025-12-19 00:34:03 -08:00
1 parent ae5c01cc78
commit 78706903a2
2641 files changed
+228363 -201264

No files matched your search

+43 -51
View File
@@ -3,19 +3,19 @@
/**
* <pre>
* Invision Power Services
* IP.Board v3.1.4
* IP.Board v3.2.3
* Upload handler : Handles $_FILES and checks for security
* Last Updated: $Date: 2010-04-14 19:25:39 -0400 (Wed, 14 Apr 2010) $
* Last Updated: $Date: 2011-06-17 07:48:26 -0400 (Fri, 17 Jun 2011) $
* </pre>
*
* @author $Author: bfarber $
* @author $Author: ips_terabyte $
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
* @license http://www.invisionpower.com/community/board/license.html
* @license This is NULLED!
* @package IP.Board
* @subpackage Kernel
* @link http://www.invisionpower.com
* @link http://hatynka.in
* @since 15th March 2004
* @version $Revision: 389 $
* @version $Revision: 9058 $
*
*
* Example Usage:
@@ -57,12 +57,21 @@
*
*/
if ( ! defined( 'IPS_FILE_PERMISSION' ) )
{
define( 'IPS_FILE_PERMISSION', 0777 );
}
if ( ! defined( 'IPS_FOLDER_PERMISSION' ) )
{
define( 'IPS_FOLDER_PERMISSION', 0777 );
}
class classUpload
{
/**
* Name of upload form field
*
* @access public
* @var string
*/
public $upload_form_field = 'FILE_UPLOAD';
@@ -71,7 +80,6 @@ class classUpload
* Out filename *without* extension
* (Leave blank to retain user filename)
*
* @access public
* @var string
*/
public $out_file_name = '';
@@ -79,7 +87,6 @@ class classUpload
/**
* Out dir (./upload) - no trailing slash
*
* @access public
* @var string
*/
public $out_file_dir = './';
@@ -87,7 +94,6 @@ class classUpload
/**
* Maximum file size of this upload
*
* @access public
* @var integer
*/
public $max_file_size = 0;
@@ -95,7 +101,6 @@ class classUpload
/**
* Forces PHP, CGI, etc to text
*
* @access public
* @var integer
*/
public $make_script_safe = 1;
@@ -103,7 +108,6 @@ class classUpload
/**
* Force non-img file extenstion (leave blank if not) (ex: 'ibf' makes upload.doc => upload.ibf)
*
* @access public
* @var string
*/
public $force_data_ext = '';
@@ -111,7 +115,6 @@ class classUpload
/**
* Allowed file extensions array( 'gif', 'jpg', 'jpeg'..)
*
* @access public
* @var array
*/
public $allowed_file_ext = array();
@@ -119,7 +122,6 @@ class classUpload
/**
* Check file extension allowed
*
* @access public
* @var boolean
*/
public $check_file_ext = true;
@@ -127,7 +129,6 @@ class classUpload
/**
* Array of IMAGE file extensions
*
* @access public
* @var array
*/
public $image_ext = array( 'gif', 'jpeg', 'jpg', 'jpe', 'png' );
@@ -135,7 +136,6 @@ class classUpload
/**
* Check to make sure an image is an image
*
* @access public
* @var boolean
*/
public $image_check = true;
@@ -143,7 +143,6 @@ class classUpload
/**
* Returns current file extension
*
* @access public
* @var string
*/
public $file_extension = '';
@@ -152,7 +151,6 @@ class classUpload
* If force_data_ext == 1, this will return the 'real' extension
* and $file_extension will return the 'force_data_ext'
*
* @access public
* @var string
*/
public $real_file_extension = '';
@@ -160,7 +158,6 @@ class classUpload
/**
* Returns error number [1-5]
*
* @access public
* @var integer
*/
public $error_no = 0;
@@ -168,7 +165,6 @@ class classUpload
/**
* Returns if upload is img or not
*
* @access public
* @var boolean
*/
public $is_image = 0;
@@ -176,7 +172,6 @@ class classUpload
/**
* Returns file name as was uploaded by user
*
* @access public
* @var string
*/
public $original_file_name = "";
@@ -184,7 +179,6 @@ class classUpload
/**
* Returns final file name as is saved on disk. (no path info)
*
* @access public
* @var string
*/
public $parsed_file_name = "";
@@ -192,7 +186,6 @@ class classUpload
/**
* Returns final file name with path info
*
* @access public
* @var string
*/
public $saved_upload_name = "";
@@ -200,7 +193,6 @@ class classUpload
/**
* Processes the upload
*
* @access public
* @return boolean Upload successful
*/
public function process()
@@ -240,7 +232,7 @@ class classUpload
or $_FILES[ $this->upload_form_field ]['name'] == ""
or !$_FILES[ $this->upload_form_field ]['name']
or !$_FILES[ $this->upload_form_field ]['size']
or ($_FILES[ $this->upload_form_field ]['name'] == "none")
or $_FILES[ $this->upload_form_field ]['name'] == "none"
)
{
if( $_FILES[ $this->upload_form_field ]['error'] == 2 )
@@ -274,6 +266,8 @@ class classUpload
}
}
$this->allowed_file_ext = array_map( 'strtolower', $this->allowed_file_ext );
//-------------------------------------------------
// Get file extension
//-------------------------------------------------
@@ -315,7 +309,7 @@ class classUpload
$this->original_file_name = $FILE_NAME;
$FILE_NAME = preg_replace( "/[^\w\.]/", "_", $FILE_NAME );
$FILE_NAME = preg_replace( '/[^\w\.]/', "_", $FILE_NAME );
//-------------------------------------------------
// Convert file name?
@@ -339,11 +333,11 @@ class classUpload
if ( $this->make_script_safe )
{
if ( preg_match( "/\.(cgi|pl|js|asp|php|html|htm|jsp|jar)(\.|$)/i", $FILE_NAME ) )
if ( preg_match( '/\.(cgi|pl|js|asp|php|html|htm|jsp|jar)(\.|$)/i', $FILE_NAME ) )
{
$FILE_TYPE = 'text/plain';
$this->file_extension = 'txt';
$this->parsed_file_name = preg_replace( "/\.(cgi|pl|js|asp|php|html|htm|jsp|jar)(\.|$)/i", "$2", $this->parsed_file_name );
$this->parsed_file_name = preg_replace( '/\.(cgi|pl|js|asp|php|html|htm|jsp|jar)(\.|$)/i', "$2", $this->parsed_file_name );
$renamed = 1;
}
@@ -388,10 +382,10 @@ class classUpload
}
else
{
@chmod( $this->saved_upload_name, 0777 );
@chmod( $this->saved_upload_name, IPS_FILE_PERMISSION );
}
if( !$renamed AND $this->file_extension != 'txt' )
if( ! $renamed AND $this->file_extension != 'txt' )
{
$this->_checkXSSInfile();
@@ -455,29 +449,25 @@ class classUpload
/**
* Checks for XSS inside file. If found, deletes file, sets error_no to 5 and returns
*
* @access private
* @return void
* @return @e void
*/
private function _checkXSSInfile()
protected function _checkXSSInfile()
{
// HTML added inside an inline file is not good in IE...
$fh = fopen( $this->saved_upload_name, 'rb' );
$file_check = fread( $fh, 512 );
fclose( $fh );
if( !$file_check )
if ( ! $file_check )
{
@unlink( $this->saved_upload_name );
$this->error_no = 5;
return false;
}
# Thanks to Nicolas Grekas from comments at www.splitbrain.org for helping to identify all vulnerable HTML tags
else if( preg_match( "#<script|<html|<head|<title|<body|<pre|<table|<a\s+href|<img|<plaintext|<cross\-domain\-policy#si", $file_check ) )
else if( preg_match( '#<script|<html|<head|<title|<body|<pre|<table|<a\s+href|<img|<plaintext|<cross\-domain\-policy#si', $file_check ) )
{
@unlink( $this->saved_upload_name );
$this->error_no = 5;
@@ -486,25 +476,27 @@ class classUpload
}
/**
* Returns the file extension of the current filename
*
* @access public
* @param string Filename
* @return string File extension
*/
* Returns the file extension of the current filename
*
* @param string Filename
* @return string File extension
*/
public function _getFileExtension($file)
{
if( class_exists('IPSText') )
{
return IPSText::getFileExtension( $file );
}
return strtolower( str_replace( ".", "", substr( $file, strrpos( $file, '.' ) ) ) );
}
/**
* Trims off trailing slashes
*
* @access private
* @return void
*/
private function _cleanPaths()
* Trims off trailing slashes
*
* @return @e void
*/
protected function _cleanPaths()
{
$this->out_file_dir = rtrim( $this->out_file_dir, '/' );
}