Version 2.1.7
This commit is contained in:
1 parent
0eecc172d9
commit
f73f8bff6d
941 files changed
+215301
-103093
No files matched your search
@@ -2,16 +2,28 @@
|
||||
|
||||
/*
|
||||
+--------------------------------------------------------------------------
|
||||
| Invision Power Board v2.0.0
|
||||
| Invision Power Board 2.1.7
|
||||
| =============================================
|
||||
| by Matthew Mecham
|
||||
| (c) 2001 - 2004 Invision Power Services, Inc.
|
||||
| (c) 2001 - 2005 Invision Power Services, Inc.
|
||||
| http://www.invisionpower.com
|
||||
| =============================================
|
||||
| Web: http://www.invisionboard.com
|
||||
| Time: Tue, 21 Sep 2004 16:34:28 GMT
|
||||
| Release: 150aa7a702c3c8b6f6eb90ad49305d2f
|
||||
| http://www.ibresource.ru/products/invisionpowerboard/
|
||||
| Time: Tuesday 18th of July 2006 05:56:00 PM
|
||||
| Release: 52f408a29988b02f45b5e6f4ba5af0ae
|
||||
| Licence Info: http://www.invisionboard.com/?license
|
||||
| http://www.ibresource.ru/license
|
||||
+---------------------------------------------------------------------------
|
||||
| INVISION POWER BOARD IS NOT FREE / OPEN SOURCE!
|
||||
+---------------------------------------------------------------------------
|
||||
| INVISION POWER BOARD ÍÅ ßÂËßÅÒÑß ÁÅÑÏËÀÒÍÛÌ ÏÐÎÃÐÀÌÌÍÛÌ ÎÁÅÑÏÅ×ÅÍÈÅÌ!
|
||||
| Ïðàâà íà ÏÎ ïðèíàäëåæàò Invision Power Services
|
||||
| Ïðàâà íà ïåðåâîä IBResource (http://www.ibresource.ru)
|
||||
+---------------------------------------------------------------------------
|
||||
| > $Date: 2005-10-10 14:03:20 +0100 (Mon, 10 Oct 2005) $
|
||||
| > $Revision: 22 $
|
||||
| > $Author: matt $
|
||||
+---------------------------------------------------------------------------
|
||||
|
|
||||
| > UPLOAD handling methods (KERNEL)
|
||||
@@ -25,58 +37,186 @@
|
||||
| 2: Not valid upload type
|
||||
| 3: Upload exceeds $max_file_size
|
||||
| 4: Could not move uploaded file, upload deleted
|
||||
| 5: File pretending to be an image but isn't (poss XSS attack)
|
||||
+--------------------------------------------------------------------------
|
||||
*/
|
||||
|
||||
/**
|
||||
* IPS Kernel Pages: Upload
|
||||
*
|
||||
* This class contains all generic functions to handle
|
||||
* the parsing of $_FILE data.
|
||||
*
|
||||
* Example Usage:
|
||||
* <code>
|
||||
* $upload = new class_upload();
|
||||
* $upload->out_file_dir = './uploads';
|
||||
* $upload->max_file_size = '10000000';
|
||||
* $upload->make_script_safe = 1;
|
||||
* $upload->allowed_file_ext = array( 'gif', 'jpg', 'jpeg', 'png' );
|
||||
* $upload->upload_process();
|
||||
*
|
||||
* if ( $upload->error_no )
|
||||
* {
|
||||
* switch( $upload->error_no )
|
||||
* {
|
||||
* case 1:
|
||||
* // No upload
|
||||
* print "No upload"; exit();
|
||||
* case 2:
|
||||
* case 5:
|
||||
* // Invalid file ext
|
||||
* print "Invalid File Extension"; exit();
|
||||
* case 3:
|
||||
* // Too big...
|
||||
* print "File too big"; exit();
|
||||
* case 4:
|
||||
* // Cannot move uploaded file
|
||||
* print "Move failed"; exit();
|
||||
* }
|
||||
* }
|
||||
* print $upload->saved_upload_name . " uploaded!";
|
||||
* </code>
|
||||
* ERRORS:
|
||||
* 1: No upload
|
||||
* 2: Not valid upload type
|
||||
* 3: Upload exceeds $max_file_size
|
||||
* 4: Could not move uploaded file, upload deleted
|
||||
* 5: File pretending to be an image but isn't (poss XSS attack)
|
||||
*
|
||||
* @package IPS_KERNEL
|
||||
* @author Matt Mecham
|
||||
* @copyright Invision Power Services, Inc.
|
||||
* @version 2.1
|
||||
*/
|
||||
|
||||
/**
|
||||
*
|
||||
*/
|
||||
|
||||
/**
|
||||
* Upload Class
|
||||
*
|
||||
* Methods and functions for handling file uploads
|
||||
*
|
||||
* @package IPS_KERNEL
|
||||
* @author Matt Mecham
|
||||
* @version 2.1
|
||||
*/
|
||||
class class_upload
|
||||
{
|
||||
// name of upload form field
|
||||
/**
|
||||
* Name of upload form field
|
||||
*
|
||||
* @var string
|
||||
*/
|
||||
var $upload_form_field = 'FILE_UPLOAD';
|
||||
|
||||
// Out filename *without* extension
|
||||
// (Leave blank to retain user filename)
|
||||
/**
|
||||
* Out filename *without* extension
|
||||
* (Leave blank to retain user filename)
|
||||
*
|
||||
* @var string
|
||||
*/
|
||||
var $out_file_name = '';
|
||||
|
||||
// Out dir (./upload) - no trailing slash
|
||||
/**
|
||||
* Out dir (./upload) - no trailing slash
|
||||
*
|
||||
* @var string
|
||||
*/
|
||||
var $out_file_dir = './';
|
||||
|
||||
// maximum file size of this upload
|
||||
/**
|
||||
* maximum file size of this upload
|
||||
*
|
||||
* @var integer
|
||||
*/
|
||||
var $max_file_size = 0;
|
||||
|
||||
// Forces PHP, CGI, etc to text
|
||||
/**
|
||||
* Forces PHP, CGI, etc to text
|
||||
*
|
||||
* @var integer
|
||||
*/
|
||||
var $make_script_safe = 1;
|
||||
|
||||
// Force non-img file extenstion (leave blank if not) (ex: 'ibf'a makes upload.doc => upload.ibf)
|
||||
/**
|
||||
* Force non-img file extenstion (leave blank if not) (ex: 'ibf' makes upload.doc => upload.ibf)
|
||||
*
|
||||
* @var string
|
||||
*/
|
||||
var $force_data_ext = '';
|
||||
|
||||
// Allowed file extensions array( 'gif', 'jpg', 'jpeg'..)
|
||||
/**
|
||||
* Allowed file extensions array( 'gif', 'jpg', 'jpeg'..)
|
||||
*
|
||||
* @var array
|
||||
*/
|
||||
var $allowed_file_ext = array();
|
||||
|
||||
// Array of IMAGE file extensions
|
||||
var $image_ext = array( 'gif', 'jpeg', 'jpg', 'png' );
|
||||
/**
|
||||
* Array of IMAGE file extensions
|
||||
*
|
||||
* @var array
|
||||
*/
|
||||
var $image_ext = array( 'gif', 'jpeg', 'jpg', 'jpe', 'png' );
|
||||
|
||||
/**
|
||||
* Check to make sure an image is an image
|
||||
*
|
||||
* @var boolean flag
|
||||
*/
|
||||
var $image_check = 1;
|
||||
|
||||
// Returns current file extension
|
||||
/**
|
||||
* Returns current file extension
|
||||
*
|
||||
* @var string
|
||||
*/
|
||||
var $file_extension = '';
|
||||
|
||||
// If force_data_ext == 1, this will return the 'real' extension
|
||||
// and $file_extension will return the 'force_data_ext'
|
||||
/**
|
||||
* If force_data_ext == 1, this will return the 'real' extension
|
||||
* and $file_extension will return the 'force_data_ext'
|
||||
*
|
||||
* @var string
|
||||
*/
|
||||
var $real_file_extension = '';
|
||||
|
||||
// Returns error number
|
||||
/**
|
||||
* Returns error number
|
||||
*
|
||||
* @var integer
|
||||
*/
|
||||
var $error_no = 0;
|
||||
|
||||
// Returns if upload is img or not
|
||||
/**
|
||||
* Returns if upload is img or not
|
||||
*
|
||||
* @var integer
|
||||
*/
|
||||
var $is_image = 0;
|
||||
|
||||
// Returns file name as was uploaded by user
|
||||
/**
|
||||
* Returns file name as was uploaded by user
|
||||
*
|
||||
* @var string
|
||||
*/
|
||||
var $original_file_name = "";
|
||||
|
||||
// Returns final file name as is saved on disk. (no path info)
|
||||
/**
|
||||
* Returns final file name as is saved on disk. (no path info)
|
||||
*
|
||||
* @var string
|
||||
*/
|
||||
var $parsed_file_name = "";
|
||||
|
||||
// Returns final file name with path info
|
||||
/**
|
||||
* Returns final file name with path info
|
||||
*
|
||||
* @var string
|
||||
*/
|
||||
var $saved_upload_name = "";
|
||||
|
||||
/*-------------------------------------------------------------------------*/
|
||||
@@ -93,10 +233,24 @@ class class_upload
|
||||
// PROCESS THE UPLOAD
|
||||
/*-------------------------------------------------------------------------*/
|
||||
|
||||
/**
|
||||
* Processes the upload
|
||||
*
|
||||
*/
|
||||
|
||||
function upload_process()
|
||||
{
|
||||
$this->_clean_paths();
|
||||
|
||||
//-------------------------------------------------
|
||||
// Check for getimagesize
|
||||
//-------------------------------------------------
|
||||
|
||||
if ( ! function_exists( 'getimagesize' ) )
|
||||
{
|
||||
$this->image_check = 0;
|
||||
}
|
||||
|
||||
//-------------------------------------------------
|
||||
// Set up some variables to stop carpals developing
|
||||
//-------------------------------------------------
|
||||
@@ -178,18 +332,6 @@ class class_upload
|
||||
|
||||
$this->original_file_name = $FILE_NAME;
|
||||
|
||||
//-------------------------------------------------
|
||||
// Is it an image?
|
||||
//-------------------------------------------------
|
||||
|
||||
if ( is_array( $this->image_ext ) and count( $this->image_ext ) )
|
||||
{
|
||||
if ( in_array( $this->file_extension, $this->image_ext ) )
|
||||
{
|
||||
$this->is_image = 1;
|
||||
}
|
||||
}
|
||||
|
||||
//-------------------------------------------------
|
||||
// Convert file name?
|
||||
// In any case, file name is WITHOUT extension
|
||||
@@ -201,7 +343,7 @@ class class_upload
|
||||
}
|
||||
else
|
||||
{
|
||||
$this->parsed_file_name = str_replace( '.'.$this->file_extension, "", $FILE_NAME );
|
||||
$this->parsed_file_name = preg_replace( '#\.'.$this->file_extension."#is", "", $FILE_NAME );
|
||||
}
|
||||
|
||||
//-------------------------------------------------
|
||||
@@ -217,6 +359,18 @@ class class_upload
|
||||
}
|
||||
}
|
||||
|
||||
//-------------------------------------------------
|
||||
// Is it an image?
|
||||
//-------------------------------------------------
|
||||
|
||||
if ( is_array( $this->image_ext ) and count( $this->image_ext ) )
|
||||
{
|
||||
if ( in_array( $this->file_extension, $this->image_ext ) )
|
||||
{
|
||||
$this->is_image = 1;
|
||||
}
|
||||
}
|
||||
|
||||
//-------------------------------------------------
|
||||
// Add on the extension...
|
||||
//-------------------------------------------------
|
||||
@@ -230,6 +384,9 @@ class class_upload
|
||||
|
||||
//-------------------------------------------------
|
||||
// Copy the upload to the uploads directory
|
||||
// ^^ We need to do this before checking the img
|
||||
// size for the openbasedir restriction peeps
|
||||
// We'll just unlink if it doesn't checkout
|
||||
//-------------------------------------------------
|
||||
|
||||
$this->saved_upload_name = $this->out_file_dir.'/'.$this->parsed_file_name;
|
||||
@@ -243,12 +400,56 @@ class class_upload
|
||||
{
|
||||
@chmod( $this->saved_upload_name, 0777 );
|
||||
}
|
||||
|
||||
//-------------------------------------------------
|
||||
// Is it an image?
|
||||
//-------------------------------------------------
|
||||
|
||||
if ( $this->is_image )
|
||||
{
|
||||
//-------------------------------------------------
|
||||
// Are we making sure its an image?
|
||||
//-------------------------------------------------
|
||||
|
||||
if ( $this->image_check )
|
||||
{
|
||||
$img_attributes = @getimagesize( $this->saved_upload_name );
|
||||
|
||||
if ( ! is_array( $img_attributes ) or ! count( $img_attributes ) )
|
||||
{
|
||||
// Unlink the file first
|
||||
@unlink( $this->saved_upload_name );
|
||||
$this->error_no = 5;
|
||||
return;
|
||||
}
|
||||
else if ( ! $img_attributes[2] )
|
||||
{
|
||||
// Unlink the file first
|
||||
@unlink( $this->saved_upload_name );
|
||||
$this->error_no = 5;
|
||||
return;
|
||||
}
|
||||
else if ( $img_attributes[2] == 1 AND ( $this->file_extension == 'jpg' OR $this->file_extension == 'jpeg' ) )
|
||||
{
|
||||
// Potential XSS attack with a fake GIF header in a JPEG
|
||||
@unlink( $this->saved_upload_name );
|
||||
$this->error_no = 5;
|
||||
return;
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/*-------------------------------------------------------------------------*/
|
||||
// INTERNAL: Get file extension
|
||||
/*-------------------------------------------------------------------------*/
|
||||
|
||||
/**
|
||||
* Returns the file extension of the current filename
|
||||
*
|
||||
* @param string Filename
|
||||
*/
|
||||
|
||||
function _get_file_extension($file)
|
||||
{
|
||||
return strtolower( str_replace( ".", "", substr( $file, strrpos( $file, '.' ) ) ) );
|
||||
@@ -258,6 +459,11 @@ class class_upload
|
||||
// INTERNAL: Clean paths
|
||||
/*-------------------------------------------------------------------------*/
|
||||
|
||||
/**
|
||||
* Trims off trailing slashes
|
||||
*
|
||||
*/
|
||||
|
||||
function _clean_paths()
|
||||
{
|
||||
$this->out_file_dir = preg_replace( "#/$#", "", $this->out_file_dir );
|
||||
|
||||
Reference in new issue
Block a user