note 26642 deleted from function.readdir by tularis

From: Date: Sun, 13 May 2007 19:07:28 +0000
Subject: note 26642 deleted from function.readdir by tularis
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-126560@lists.php.net to get a copy of this message
Note Submitter: Silphy@nowhere ---- Mod'ed the code a bit. Made it so the dir is selected by dir.php?dir=name . I made it to parse anything starting with "/" "." or "./" so there shouldn't be any security risks when using this. <?php $directory = $_REQUEST["dir"]; // lets fetch the variable: REQUEST works for both, POST and GET methods if (substr($directory, 0, 1) == "/") $directory = ""; $directory = str_replace ("./", "", $directory); $directory = str_replace (".", "", $directory); if ($directory != @$null) { // lets check if the variable "dir" has something in it, otherwise lets just print out the empty document if ($dir = @opendir($directory)) { // changed "./" to the directory variable echo ("Listing contents of <b>$directory</b><br><br>\n"); // i just added this thing while (($file = readdir($dir)) !== false) { if ($file != "." && $file != "..") { $location = "$directory/$file"; $type = filetype($location); $size = filesize($location); if (is_dir($location) == true) { echo ("$type - <a href=\"dir.php?dir=$location\">$file</a><br>\n"); } else { echo ("$type - <a href=\"$location\">$file</a> - $size Bytes<br>\n"); } } } closedir($dir); } } ?>

« previous php.notes (#126560) next »