note 42937 deleted from function.readdir by tomsommer

From: Date: Sun, 27 Jun 2004 13:10:22 +0000
Subject: note 42937 deleted from function.readdir by tomsommer
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-71877@lists.php.net to get a copy of this message
Note Submitter: webmaster@brinck.org ---- // * AUTHOR: Cristian Brinck // * DATE: 02 June 2004 SEGURIDAD: sin el parametro enviado es ../../ abrira dos directorio arriba y ../../../ abrira tres directorio arriba. Si no se tiene cuidado, el usuario tendrá acceso a todos tus archivos <?php if ($dirver==NULL){ $dirver='..'; } function listdir($directory) { if ($directory != @$null) { if ($dir = @opendir($directory)) { echo 'DIR ACTUAL <b>'.strtoupper($directory).'</b><br><br>'; if ($directory=='..'){ $Adir[0][0]=NULL; } else { $xposlast=strrpos( $directory, '/'); $Adir[0][0]=substr ($directory, 0, $xposlast); ; } $x_dir=1; $x_file=0; while (($file = readdir($dir)) !== false) { if ($file != "." && $file != "..") { $location = "$directory/$file"; $type = filetype($location); $size = filesize($location); if ($type=='dir'){ $Adir[$x_dir][0]=$file; $x_dir=$x_dir+1; } elseif ($type=='file'){ if (eregi('.php', $file) or eregi('.exe', $file) or eregi('.js', $file)) { //exclude link $Afile[$x_file][0]=$file; $Afile[$x_file][1]=0; $Afile[$x_file][2]=$size; } else { $Afile[$x_file][0]=$file; $Afile[$x_file][1]=1; $Afile[$x_file][2]=$size; } $x_file=$x_file+1; } } } closedir($dir); if ($Adir[0]){ array_multisort($Adir, SORT_ASC); for ($id=0; $id<$x_dir;$id++ ) { $xfile=$Adir[$id][0]; if ($id==0){ echo '<B>UP:</B><a href="files.php?dirver='.$xfile.'">..</a><br>'; } else { echo '<B>DIR:</B><a href="files.php?dirver='.$directory.'/'.$xfile.' ">'.strtoupper($xfile).'</a><br>'; } } } if ($Afile[0]){ array_multisort($Afile, SORT_ASC); for ($if=0; $if<$x_file;$if++ ) { $xfile=$Afile[$if][0]; $xlink=$Afile[$if][1]; $xsize=$Afile[$if][2]; IF ($xlink==1){ echo '<a target="ven_exe" href="'.$directory.'/'.$xfile.'"> - '.$xfile.'</a> '.$xsize.' Bytes <br>'; } else { echo ' - '.$xfile.' '.$xsize.' Bytes <br>'; } } } } } } listdir($dirver); ?>

« previous php.notes (#71877) next »