Project

General

Profile

« Previous | Next » 

Revision 1475

Added by Dietmar almost 13 years ago

+ add SecureForm.mtab.php under mantennance by WebsiteBaker Community
! security fixes media, groups, users, sections
  1. change lang variable to remove upgrade-script
    ! reworked add sections in pages
    ! fix set empty href in show_menu2
    ! set show_menu2 version to 4.9.6
    ! reworked Droplet LoginBox, add redirect query
    - remove unneeded folder js
    ! set Droplet to version 1.1.0
    + add checkboxes to change frontend absolute url to relative urls
    ! set output_filter version to 0.2

View differences:

browse.php
94 94
				$currentHome
95 95
				:
96 96
				$admin->strip_slashes($admin->get_get('dir')) ;
97

  
97 98
if($directory == '/' OR $directory == '\\') {
98 99
	$directory = '';
99 100
}
100 101

  
102
$dir_backlink = 'browse.php?dir='.$directory;
103

  
101 104
// Check to see if it contains ../
102 105
if (!check_media_path($directory)) {
103 106
	// $admin->print_header();
......
159 162

  
160 163
if($handle = opendir(WB_PATH.MEDIA_DIRECTORY.'/'.$directory)) {
161 164
	// Loop through the files and dirs an add to list
162
	while(false !== ($file = readdir($handle))) {
165
   while (false !== ($file = readdir($handle))) {
166
		$info = pathinfo($file);
167
		$ext = isset($info['extension']) ? $info['extension'] : '';
163 168
		if(substr($file, 0, 1) != '.' AND $file != '.svn' AND $file != 'index.php') {
164
			if(is_dir(WB_PATH.MEDIA_DIRECTORY.$directory.'/'.$file)) {
165
				if(!isset($home_folders[$directory.'/'.$file])) {
166
					$DIR[] = $file;
167
				}
168
			} else {
169
				$info = pathinfo($file);
170
				$ext = isset($info['extension']) ? $info['extension'] : '';
171
				if( !preg_match('/'.$forbidden_file_types.'$/i', $ext) ) {
169
			if( !preg_match('/'.$forbidden_file_types.'$/i', $ext) ) {
170
				if(is_dir(WB_PATH.MEDIA_DIRECTORY.$directory.'/'.$file)) {
171
					if(!isset($home_folders[$directory.'/'.$file])) {
172
						$DIR[] = $file;
173
					}
174
				} else {
172 175
					$FILE[] = $file;
173 176
				}
174 177
			}
......
186 189
								'NAME' => $name,
187 190
								'NAME_SLASHED' => addslashes($name),
188 191
								'TEMP_ID' => $admin->getIDKEY($temp_id),
192
								// 'TEMP_ID' => $temp_id,
189 193
								'LINK' => "browse.php?dir=$directory/$link_name",
190 194
								'LINK_TARGET' => '_self',
191 195
								'ROW_BG_COLOR' => $row_bg_color,
......
246 250
								'NAME' => $name,
247 251
								'NAME_SLASHED' => addslashes($name),
248 252
								'TEMP_ID' => $admin->getIDKEY($temp_id),
253
								// 'TEMP_ID' => $temp_id,
249 254
								'LINK' => WB_URL.MEDIA_DIRECTORY.$directory.'/'.$name,
250 255
								'LINK_TARGET' => '_blank',
251 256
								'ROW_BG_COLOR' => $row_bg_color,

Also available in: Unified diff