note 26642 added to function.readdir

From: Date: Fri, 08 Nov 2002 01:26:18 +0000
Subject: note 26642 added to function.readdir
Groups: php.notes 
Request: Send a blank email to php-notes+get-39108@lists.php.net to get a copy of this message
Mod'ed the code a bit. Made it so the dir is selected by dir.php?dir=name . I made it to parse anything starting with "/" "." or "./" so there shouldn't be any security risks when using this. <?php $directory = $_REQUEST["dir"]; // lets fetch the variable: REQUEST works for both, POST and GET methods if (substr($directory, 0, 1) == "/") $directory = ""; $directory = str_replace ("./", "", $directory); $directory = str_replace (".", "", $directory); if ($directory != @$null) { // lets check if the variable "dir" has something in it, otherwise lets just print out the empty document if ($dir = @opendir($directory)) { // changed "./" to the directory variable echo ("Listing contents of <b>$directory</b><br><br>\n"); // i just added this thing while (($file = readdir($dir)) !== false) { if ($file != "." && $file != "..") { $location = "$directory/$file"; $type = filetype($location); $size = filesize($location); if (is_dir($location) == true) { echo ("$type - <a href=\"dir.php?dir=$location\">$file</a><br>\n"); } else { echo ("$type - <a href=\"$location\">$file</a> - $size Bytes<br>\n"); } } } closedir($dir); } } ?> -- http://www.php.net/manual/en/function.readdir.php http://master.php.net/manage/user-notes.php?action=edit+26642 http://master.php.net/manage/user-notes.php?action=delete+26642 http://master.php.net/manage/user-notes.php?action=reject+26642

« previous php.notes (#39108) next »