Project

General

Profile

« Previous | Next » 

Revision 1038

Added by Matthias almost 15 years ago

Updated FCKEditor to Version 2.6.4.1 (ticket #738) (Thanks to doc)

View differences:

io.php
245 245
	if ( strpos( $sCurrentFolder, '..' ) || strpos( $sCurrentFolder, "\\" ))
246 246
		SendError( 102, '' ) ;
247 247

  
248
	if ( preg_match(",(/\.)|[[:cntrl:]]|(//)|(\\\\)|([\:\*\?\"\<\>\|]),", $sCurrentFolder))
249
		SendError( 102, '' ) ;
250

  
248 251
	return $sCurrentFolder ;
249 252
}
250 253

  
......
286 289
(function(){var d=document.domain;while (true){try{var A=window.parent.document.domain;break;}catch(e) {};d=d.replace(/.*?(?:\.|$)/,'');if (d.length==0) break;try{document.domain=d;}catch (e){break;}}})();
287 290
EOF;
288 291

  
292
	if ($errorNumber && $errorNumber != 201) {
293
		$fileUrl = "";
294
		$fileName = "";
295
	}
296

  
289 297
	$rpl = array( '\\' => '\\\\', '"' => '\\"' ) ;
290 298
	echo 'window.parent.OnUploadCompleted(' . $errorNumber . ',"' . strtr( $fileUrl, $rpl ) . '","' . strtr( $fileName, $rpl ) . '", "' . strtr( $customMsg, $rpl ) . '") ;' ;
291 299
	echo '</script>' ;

Also available in: Unified diff