Correction d'une faille permettant de creer des fichiers dans d'autres repertoires que le home du membre.

This commit is contained in:
Nahuel Angelinetti 2006-11-27 18:29:23 +00:00
parent 3f648fcf1e
commit 7ce09ce35b
1 changed files with 1 additions and 1 deletions

View File

@ -282,7 +282,7 @@ class m_bro {
global $db,$err,$cuid; global $db,$err,$cuid;
$file=ssla($file); $file=ssla($file);
$absolute=$this->convertabsolute($dir."/".$file,0); $absolute=$this->convertabsolute($dir."/".$file,0);
if ($absolute && !file_exists($absolute)) { if ($absolute && !file_exists($absolute) && checkuserpath($absolute."/".$file) != 0) {
touch($absolute); touch($absolute);
$db->query("UPDATE browser SET crff=0 WHERE uid='$cuid';"); $db->query("UPDATE browser SET crff=0 WHERE uid='$cuid';");
return true; return true;