note 48961 added to ref.dir
| From: | selfsimilar at yahoo dot com | Date: | Thu, 13 Jan 2005 08:44:25 +0000 |
| Subject: | note 48961 added to ref.dir | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-83192@lists.php.net to get a copy of this message | ||
David's script is great, but there are a few problems if you really want to use it. If
you're worried about security you probably shouldn't use this anyways, but with
David's code, an inquisitive person could manually send a uri that ends in
"?moverse=../" and still move up a directory. Also, at least with the version of PHP on my
server (unsure of version), any uri with a single quote (') would end up with a backslash
preceding it. I think this is more to do with using the GET method instead of POST, but I
haven't delved that deep. I also added some '\n' action for html readability and
replaced whitespace with percentage codes.
<?php
$path = "./";
if (strrpos($moverse,'..')) {
$moverse = str_replace('/..','',$moverse);
$moverse = substr($moverse,0,strrpos($moverse,'/'));
}
if (strpos($moverse,'..')===false) { // php is weakly typed
} else if (strpos($moverse,'..')==0) {
echo '<span style="font-size: 150%;"><b>Bad Hacker = No
caffeine</b></span>';
$moverse="";
}
if($moverse) {
$moverse = $moverse."/";
if (strpos($moverse,"\'")) { // This corrects a uri that includes single quote(s),
which I think gets messed up by GET
$moverse = str_replace("\'","'",$moverse);
}
}
echo $moverse."<br/>"."\n";
$handle=opendir($path.$moverse);
while ($file = readdir($handle)) {
if(is_dir($path.$moverse.$file) && $file != ".") {
if ($file == ".." && $moverse == "") {
} else {
$uri=str_replace(" ","%20",$moverse.$file);
echo '<a
href="?moverse='.$uri.'">'.$file.'</a><br/>'."\n";
}
} else if ($file != "." && $file != "index.php") {
$uri=str_replace(" ","%20",$path.$moverse.$file);
echo '<a
href="'.$uri.'">'.$file.'</a><br/>'."\n";
}
}
?>
----
Manual Page -- http://www.php.net/manual/en/ref.dir.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+48961
Delete -- http://master.php.net/manage/user-notes.php?action=delete+48961&report=yes
Reason: bad code -- http://master.php.net/manage/user-notes.php?action=delete+48961&report=yes&reason=bad+code
Reason: spam -- http://master.php.net/manage/user-notes.php?action=delete+48961&report=yes&reason=spam
Reason: useless example -- http://master.php.net/manage/user-notes.php?action=delete+48961&report=yes&reason=useless+example
Reason: contains commercial links -- http://master.php.net/manage/user-notes.php?action=delete+48961&report=yes&reason=contains+commercial+links
Reason: useless note -- http://master.php.net/manage/user-notes.php?action=delete+48961&report=yes&reason=useless+note
Reject -- http://master.php.net/manage/user-notes.php?action=reject+48961&report=yes
Search -- http://master.php.net/manage/user-notes.php