('Your file was not uploaded correctly. You may succeed in retrying. ');
break;
case UPLOAD_ERR_NO_TMP_DIR:
case UPLOAD_ERR_CANT_WRITE:
case UPLOAD_ERR_EXTENSION:
('Your file was not uploaded correctly. You may succeed in retrying. ');
break;
case UPLOAD_ERR_NO_TMP_DIR:
case UPLOAD_ERR_CANT_WRITE:
case UPLOAD_ERR_EXTENSION:
- if (strcmp ($link, '.') == 0 || strcmp ($link, '..') == 0)
+ if (strcmp ($link, '.') == 0 || strcmp ($link, '..') == 0 ||
+ preg_match ('/\.tmp/i', "$link"))
- echo '<td>' . _('Filename') . '</td>';
- echo '<td>' . _('Type') . '</td>';
- echo '<td>' . _('Size') . '</td>';
- echo '<td>' . _('Expire') . '</td>';
- echo '<td>' . _('Onetime') . '</td>';
- echo '<td>' . _('Upload date') . '</td>';
- echo '<td>' . _('Origin') . '</td>';
- echo '<td>' . _('Action') . '</td>';
+ echo '<td>' . t('Filename') . '</td>';
+ echo '<td>' . t('Type') . '</td>';
+ echo '<td>' . t('Size') . '</td>';
+ echo '<td>' . t('Expire') . '</td>';
+ echo '<td>' . t('Onetime') . '</td>';
+ echo '<td>' . t('Upload date') . '</td>';
+ echo '<td>' . t('Origin') . '</td>';
+ echo '<td>' . t('Action') . '</td>';
- if (strcmp ($link, '.') == 0 || strcmp ($link, '..') == 0)
+ if (strcmp ($link, '.') == 0 || strcmp ($link, '..') == 0 ||
+ preg_match ('/\.tmp/i', "$link"))
'<form action = "admin.php" method = "post">' .
'<input type = "hidden" name = "action" value = "delete_link"/>' .
'<input type = "hidden" name = "link" value = "' . $link . '"/>' .
'<form action = "admin.php" method = "post">' .
'<input type = "hidden" name = "action" value = "delete_link"/>' .
'<input type = "hidden" name = "link" value = "' . $link . '"/>' .
'</form>' .
'<form action = "admin.php" method = "post">' .
'<input type = "hidden" name = "action" value = "delete_file"/>' .
'<input type = "hidden" name = "md5" value = "' . $l['md5'] . '"/>' .
'</form>' .
'<form action = "admin.php" method = "post">' .
'<input type = "hidden" name = "action" value = "delete_file"/>' .
'<input type = "hidden" name = "md5" value = "' . $l['md5'] . '"/>' .
- if (strcmp ($link, '.') == 0 || strcmp ($link, '..') == 0)
+ if (strcmp ($link, '.') == 0 || strcmp ($link, '..') == 0 ||
+ preg_match ('/\.tmp/i', "$link"))
- if ($l['time'] > 0 && $l['time'] < time ())
+ if ($l['time'] > 0 && $l['time'] < time () || // expired
+ !file_exists (VAR_FILES . $l['md5']) || // invalid
+ !file_exists (VAR_FILES . $l['md5'] . '_count')) // invalid