From 78c9d1494b12158c0757ca2750c73f69ae4d3e3e Mon Sep 17 00:00:00 2001 From: Axel ROGER Date: Thu, 18 Apr 2013 14:24:54 +0000 Subject: [PATCH] Fixes #1486 --- bureau/class/m_bro.php | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/bureau/class/m_bro.php b/bureau/class/m_bro.php index 5628c61f..7e483395 100644 --- a/bureau/class/m_bro.php +++ b/bureau/class/m_bro.php @@ -106,15 +106,15 @@ class m_bro { // verifier que le repertoire est dans le home de l'usgaer if (substr($dir,0,strlen($root))!=$root) { return false; - } - + } + // recomposer le chemin $dir = $dir . '/' . $file; - # Si on tente de mettre un '..' alors erreur - if ( preg_match("/\/\.\.\//", $dir) || preg_match("/\/\.\.$/", $dir) ) { - return false; - } + # Si on tente de mettre un '..' alors erreur + if ( preg_match("/\/\.\.\//", $dir) || preg_match("/\/\.\.$/", $dir) ) { + return false; + } if ($strip) { $dir=substr($dir,strlen($root)); @@ -472,7 +472,7 @@ class m_bro { if ($new[0] != '/') { $new = $old . '/' . $new; - } + } $new = $this->convertabsolute($new,0); if (!$new) {