Version 3.4.5
This commit is contained in:
1 parent
fb6b5baabc
commit
e4478369d8
1360 files changed
+228921
-179445
No files matched your search
@@ -3,19 +3,19 @@
|
||||
/**
|
||||
* <pre>
|
||||
* Invision Power Services
|
||||
* IP.Board v3.3.4
|
||||
* IP.Board v3.4.5
|
||||
* Upload handler : Handles $_FILES and checks for security
|
||||
* Last Updated: $Date: 2012-06-12 10:14:49 -0400 (Tue, 12 Jun 2012) $
|
||||
* Last Updated: $Date: 2013-02-19 06:02:12 -0500 (Tue, 19 Feb 2013) $
|
||||
* </pre>
|
||||
*
|
||||
* @author $Author: bfarber $
|
||||
* @author $Author: mmecham $
|
||||
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/company/standards.php#license
|
||||
* @package IP.Board
|
||||
* @subpackage Kernel
|
||||
* @link http://www.invisionpower.com
|
||||
* @since 15th March 2004
|
||||
* @version $Revision: 10914 $
|
||||
* @version $Revision: 12001 $
|
||||
*
|
||||
*
|
||||
* Example Usage:
|
||||
@@ -472,7 +472,7 @@ class classUpload
|
||||
return false;
|
||||
}
|
||||
# Thanks to Nicolas Grekas from comments at www.splitbrain.org for helping to identify all vulnerable HTML tags
|
||||
else if( preg_match( '#<script|<html|<head|<title|<body|<pre|<table|<a\s+href|<img|<plaintext|<cross\-domain\-policy#si', $file_check ) )
|
||||
else if( preg_match( '#(<script|<html|<head|<title|<body|<pre|<table|<a\s+href|<img|<plaintext|<cross\-domain\-policy)(\s|=|>)#si', $file_check ) )
|
||||
{
|
||||
@unlink( $this->saved_upload_name );
|
||||
$this->error_no = 5;
|
||||
|
||||
Reference in new issue
Block a user