Version 3.2.3
This commit is contained in:
1 parent
ae5c01cc78
commit
78706903a2
2641 files changed
+228363
-201264
No files matched your search
@@ -3,19 +3,19 @@
|
||||
/**
|
||||
* <pre>
|
||||
* Invision Power Services
|
||||
* IP.Board v3.1.4
|
||||
* IP.Board v3.2.3
|
||||
* Upload handler : Handles $_FILES and checks for security
|
||||
* Last Updated: $Date: 2010-04-14 19:25:39 -0400 (Wed, 14 Apr 2010) $
|
||||
* Last Updated: $Date: 2011-06-17 07:48:26 -0400 (Fri, 17 Jun 2011) $
|
||||
* </pre>
|
||||
*
|
||||
* @author $Author: bfarber $
|
||||
* @author $Author: ips_terabyte $
|
||||
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/community/board/license.html
|
||||
* @license This is NULLED!
|
||||
* @package IP.Board
|
||||
* @subpackage Kernel
|
||||
* @link http://www.invisionpower.com
|
||||
* @link http://hatynka.in
|
||||
* @since 15th March 2004
|
||||
* @version $Revision: 389 $
|
||||
* @version $Revision: 9058 $
|
||||
*
|
||||
*
|
||||
* Example Usage:
|
||||
@@ -57,12 +57,21 @@
|
||||
*
|
||||
*/
|
||||
|
||||
if ( ! defined( 'IPS_FILE_PERMISSION' ) )
|
||||
{
|
||||
define( 'IPS_FILE_PERMISSION', 0777 );
|
||||
}
|
||||
|
||||
if ( ! defined( 'IPS_FOLDER_PERMISSION' ) )
|
||||
{
|
||||
define( 'IPS_FOLDER_PERMISSION', 0777 );
|
||||
}
|
||||
|
||||
class classUpload
|
||||
{
|
||||
/**
|
||||
* Name of upload form field
|
||||
*
|
||||
* @access public
|
||||
* @var string
|
||||
*/
|
||||
public $upload_form_field = 'FILE_UPLOAD';
|
||||
@@ -71,7 +80,6 @@ class classUpload
|
||||
* Out filename *without* extension
|
||||
* (Leave blank to retain user filename)
|
||||
*
|
||||
* @access public
|
||||
* @var string
|
||||
*/
|
||||
public $out_file_name = '';
|
||||
@@ -79,7 +87,6 @@ class classUpload
|
||||
/**
|
||||
* Out dir (./upload) - no trailing slash
|
||||
*
|
||||
* @access public
|
||||
* @var string
|
||||
*/
|
||||
public $out_file_dir = './';
|
||||
@@ -87,7 +94,6 @@ class classUpload
|
||||
/**
|
||||
* Maximum file size of this upload
|
||||
*
|
||||
* @access public
|
||||
* @var integer
|
||||
*/
|
||||
public $max_file_size = 0;
|
||||
@@ -95,7 +101,6 @@ class classUpload
|
||||
/**
|
||||
* Forces PHP, CGI, etc to text
|
||||
*
|
||||
* @access public
|
||||
* @var integer
|
||||
*/
|
||||
public $make_script_safe = 1;
|
||||
@@ -103,7 +108,6 @@ class classUpload
|
||||
/**
|
||||
* Force non-img file extenstion (leave blank if not) (ex: 'ibf' makes upload.doc => upload.ibf)
|
||||
*
|
||||
* @access public
|
||||
* @var string
|
||||
*/
|
||||
public $force_data_ext = '';
|
||||
@@ -111,7 +115,6 @@ class classUpload
|
||||
/**
|
||||
* Allowed file extensions array( 'gif', 'jpg', 'jpeg'..)
|
||||
*
|
||||
* @access public
|
||||
* @var array
|
||||
*/
|
||||
public $allowed_file_ext = array();
|
||||
@@ -119,7 +122,6 @@ class classUpload
|
||||
/**
|
||||
* Check file extension allowed
|
||||
*
|
||||
* @access public
|
||||
* @var boolean
|
||||
*/
|
||||
public $check_file_ext = true;
|
||||
@@ -127,7 +129,6 @@ class classUpload
|
||||
/**
|
||||
* Array of IMAGE file extensions
|
||||
*
|
||||
* @access public
|
||||
* @var array
|
||||
*/
|
||||
public $image_ext = array( 'gif', 'jpeg', 'jpg', 'jpe', 'png' );
|
||||
@@ -135,7 +136,6 @@ class classUpload
|
||||
/**
|
||||
* Check to make sure an image is an image
|
||||
*
|
||||
* @access public
|
||||
* @var boolean
|
||||
*/
|
||||
public $image_check = true;
|
||||
@@ -143,7 +143,6 @@ class classUpload
|
||||
/**
|
||||
* Returns current file extension
|
||||
*
|
||||
* @access public
|
||||
* @var string
|
||||
*/
|
||||
public $file_extension = '';
|
||||
@@ -152,7 +151,6 @@ class classUpload
|
||||
* If force_data_ext == 1, this will return the 'real' extension
|
||||
* and $file_extension will return the 'force_data_ext'
|
||||
*
|
||||
* @access public
|
||||
* @var string
|
||||
*/
|
||||
public $real_file_extension = '';
|
||||
@@ -160,7 +158,6 @@ class classUpload
|
||||
/**
|
||||
* Returns error number [1-5]
|
||||
*
|
||||
* @access public
|
||||
* @var integer
|
||||
*/
|
||||
public $error_no = 0;
|
||||
@@ -168,7 +165,6 @@ class classUpload
|
||||
/**
|
||||
* Returns if upload is img or not
|
||||
*
|
||||
* @access public
|
||||
* @var boolean
|
||||
*/
|
||||
public $is_image = 0;
|
||||
@@ -176,7 +172,6 @@ class classUpload
|
||||
/**
|
||||
* Returns file name as was uploaded by user
|
||||
*
|
||||
* @access public
|
||||
* @var string
|
||||
*/
|
||||
public $original_file_name = "";
|
||||
@@ -184,7 +179,6 @@ class classUpload
|
||||
/**
|
||||
* Returns final file name as is saved on disk. (no path info)
|
||||
*
|
||||
* @access public
|
||||
* @var string
|
||||
*/
|
||||
public $parsed_file_name = "";
|
||||
@@ -192,7 +186,6 @@ class classUpload
|
||||
/**
|
||||
* Returns final file name with path info
|
||||
*
|
||||
* @access public
|
||||
* @var string
|
||||
*/
|
||||
public $saved_upload_name = "";
|
||||
@@ -200,7 +193,6 @@ class classUpload
|
||||
/**
|
||||
* Processes the upload
|
||||
*
|
||||
* @access public
|
||||
* @return boolean Upload successful
|
||||
*/
|
||||
public function process()
|
||||
@@ -240,7 +232,7 @@ class classUpload
|
||||
or $_FILES[ $this->upload_form_field ]['name'] == ""
|
||||
or !$_FILES[ $this->upload_form_field ]['name']
|
||||
or !$_FILES[ $this->upload_form_field ]['size']
|
||||
or ($_FILES[ $this->upload_form_field ]['name'] == "none")
|
||||
or $_FILES[ $this->upload_form_field ]['name'] == "none"
|
||||
)
|
||||
{
|
||||
if( $_FILES[ $this->upload_form_field ]['error'] == 2 )
|
||||
@@ -274,6 +266,8 @@ class classUpload
|
||||
}
|
||||
}
|
||||
|
||||
$this->allowed_file_ext = array_map( 'strtolower', $this->allowed_file_ext );
|
||||
|
||||
//-------------------------------------------------
|
||||
// Get file extension
|
||||
//-------------------------------------------------
|
||||
@@ -315,7 +309,7 @@ class classUpload
|
||||
|
||||
$this->original_file_name = $FILE_NAME;
|
||||
|
||||
$FILE_NAME = preg_replace( "/[^\w\.]/", "_", $FILE_NAME );
|
||||
$FILE_NAME = preg_replace( '/[^\w\.]/', "_", $FILE_NAME );
|
||||
|
||||
//-------------------------------------------------
|
||||
// Convert file name?
|
||||
@@ -339,11 +333,11 @@ class classUpload
|
||||
|
||||
if ( $this->make_script_safe )
|
||||
{
|
||||
if ( preg_match( "/\.(cgi|pl|js|asp|php|html|htm|jsp|jar)(\.|$)/i", $FILE_NAME ) )
|
||||
if ( preg_match( '/\.(cgi|pl|js|asp|php|html|htm|jsp|jar)(\.|$)/i', $FILE_NAME ) )
|
||||
{
|
||||
$FILE_TYPE = 'text/plain';
|
||||
$this->file_extension = 'txt';
|
||||
$this->parsed_file_name = preg_replace( "/\.(cgi|pl|js|asp|php|html|htm|jsp|jar)(\.|$)/i", "$2", $this->parsed_file_name );
|
||||
$this->parsed_file_name = preg_replace( '/\.(cgi|pl|js|asp|php|html|htm|jsp|jar)(\.|$)/i', "$2", $this->parsed_file_name );
|
||||
|
||||
$renamed = 1;
|
||||
}
|
||||
@@ -388,10 +382,10 @@ class classUpload
|
||||
}
|
||||
else
|
||||
{
|
||||
@chmod( $this->saved_upload_name, 0777 );
|
||||
@chmod( $this->saved_upload_name, IPS_FILE_PERMISSION );
|
||||
}
|
||||
|
||||
if( !$renamed AND $this->file_extension != 'txt' )
|
||||
if( ! $renamed AND $this->file_extension != 'txt' )
|
||||
{
|
||||
$this->_checkXSSInfile();
|
||||
|
||||
@@ -455,29 +449,25 @@ class classUpload
|
||||
/**
|
||||
* Checks for XSS inside file. If found, deletes file, sets error_no to 5 and returns
|
||||
*
|
||||
* @access private
|
||||
* @return void
|
||||
* @return @e void
|
||||
*/
|
||||
private function _checkXSSInfile()
|
||||
protected function _checkXSSInfile()
|
||||
{
|
||||
// HTML added inside an inline file is not good in IE...
|
||||
|
||||
$fh = fopen( $this->saved_upload_name, 'rb' );
|
||||
|
||||
$file_check = fread( $fh, 512 );
|
||||
|
||||
fclose( $fh );
|
||||
|
||||
if( !$file_check )
|
||||
if ( ! $file_check )
|
||||
{
|
||||
@unlink( $this->saved_upload_name );
|
||||
$this->error_no = 5;
|
||||
return false;
|
||||
}
|
||||
|
||||
# Thanks to Nicolas Grekas from comments at www.splitbrain.org for helping to identify all vulnerable HTML tags
|
||||
|
||||
else if( preg_match( "#<script|<html|<head|<title|<body|<pre|<table|<a\s+href|<img|<plaintext|<cross\-domain\-policy#si", $file_check ) )
|
||||
else if( preg_match( '#<script|<html|<head|<title|<body|<pre|<table|<a\s+href|<img|<plaintext|<cross\-domain\-policy#si', $file_check ) )
|
||||
{
|
||||
@unlink( $this->saved_upload_name );
|
||||
$this->error_no = 5;
|
||||
@@ -486,25 +476,27 @@ class classUpload
|
||||
}
|
||||
|
||||
/**
|
||||
* Returns the file extension of the current filename
|
||||
*
|
||||
* @access public
|
||||
* @param string Filename
|
||||
* @return string File extension
|
||||
*/
|
||||
* Returns the file extension of the current filename
|
||||
*
|
||||
* @param string Filename
|
||||
* @return string File extension
|
||||
*/
|
||||
public function _getFileExtension($file)
|
||||
{
|
||||
if( class_exists('IPSText') )
|
||||
{
|
||||
return IPSText::getFileExtension( $file );
|
||||
}
|
||||
|
||||
return strtolower( str_replace( ".", "", substr( $file, strrpos( $file, '.' ) ) ) );
|
||||
}
|
||||
|
||||
/**
|
||||
* Trims off trailing slashes
|
||||
*
|
||||
* @access private
|
||||
* @return void
|
||||
*/
|
||||
|
||||
private function _cleanPaths()
|
||||
* Trims off trailing slashes
|
||||
*
|
||||
* @return @e void
|
||||
*/
|
||||
protected function _cleanPaths()
|
||||
{
|
||||
$this->out_file_dir = rtrim( $this->out_file_dir, '/' );
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user