note 26642 deleted from function.readdir by tularis
| From: | tularis@php.net | Date: | Sun, 13 May 2007 19:07:28 +0000 |
| Subject: | note 26642 deleted from function.readdir by tularis | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-126560@lists.php.net to get a copy of this message | ||
Note Submitter: Silphy@nowhere
----
Mod'ed the code a bit. Made it so the dir is selected by dir.php?dir=name . I made it to parse
anything starting with "/" "." or "./" so there shouldn't be any
security risks when using this.
<?php
$directory = $_REQUEST["dir"]; // lets fetch the variable: REQUEST works for both, POST
and GET methods
if (substr($directory, 0, 1) == "/")
$directory = "";
$directory = str_replace ("./", "", $directory);
$directory = str_replace (".", "", $directory);
if ($directory != @$null) { // lets check if the variable "dir" has something in it,
otherwise lets just print out the empty document
if ($dir = @opendir($directory)) { // changed "./" to the directory variable
echo ("Listing contents of <b>$directory</b><br><br>\n"); // i
just added this thing
while (($file = readdir($dir)) !== false) {
if ($file != "." && $file != "..") {
$location = "$directory/$file";
$type = filetype($location);
$size = filesize($location);
if (is_dir($location) == true) {
echo ("$type - <a
href=\"dir.php?dir=$location\">$file</a><br>\n");
}
else {
echo ("$type - <a href=\"$location\">$file</a> - $size
Bytes<br>\n");
}
}
}
closedir($dir);
}
}
?>