note 48961 deleted from ref.dir by sniper
| From: | sniper@php.net | Date: | Fri, 16 Dec 2005 00:01:04 +0000 |
| Subject: | note 48961 deleted from ref.dir by sniper | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-100265@lists.php.net to get a copy of this message | ||
Note Submitter: selfsimilar at yahoo dot com
----
David's script is great, but there are a few problems if you really want to use it. If
you're worried about security you probably shouldn't use this anyways, but with
David's code, an inquisitive person could manually send a uri that ends in
"?moverse=../" and still move up a directory. Also, at least with the version of PHP on my
server (unsure of version), any uri with a single quote (') would end up with a backslash
preceding it. I think this is more to do with using the GET method instead of POST, but I
haven't delved that deep. I also added some '\n' action for html readability and
replaced whitespace with percentage codes.
<?php
$path = "./";
if (strrpos($moverse,'..')) {
$moverse = str_replace('/..','',$moverse);
$moverse = substr($moverse,0,strrpos($moverse,'/'));
}
if (strpos($moverse,'..')===false) { // php is weakly typed
} else if (strpos($moverse,'..')==0) {
echo '<span style="font-size: 150%;"><b>Bad Hacker = No
caffeine</b></span>';
$moverse="";
}
if($moverse) {
$moverse = $moverse."/";
if (strpos($moverse,"\'")) { // This corrects a uri that includes single quote(s),
which I think gets messed up by GET
$moverse = str_replace("\'","'",$moverse);
}
}
echo $moverse."<br/>"."\n";
$handle=opendir($path.$moverse);
while ($file = readdir($handle)) {
if(is_dir($path.$moverse.$file) && $file != ".") {
if ($file == ".." && $moverse == "") {
} else {
$uri=str_replace(" ","%20",$moverse.$file);
echo '<a
href="?moverse='.$uri.'">'.$file.'</a><br/>'."\n";
}
} else if ($file != "." && $file != "index.php") {
$uri=str_replace(" ","%20",$path.$moverse.$file);
echo '<a
href="'.$uri.'">'.$file.'</a><br/>'."\n";
}
}
?>