Dotclear

Changeset 3267:1c79c0953db8 for inc


Ignore:
Timestamp:
07/12/16 08:29:10 (9 years ago)
Author:
franck <carnet.franck.paul@…>
Branch:
default
Message:

Prevents .htaccess upload, thanks wiswat for reporting this.

Location:
inc
Files:
2 edited

Legend:

Unmodified
Added
Removed
  • inc/core/class.dc.core.php

    r3266 r3267  
    13961396                    array('lang','string','en', 
    13971397                    'Default blog language'), 
    1398                     array('media_exclusion','string','/\.(phps?|pht(ml)?|phl|s?html?|js)[0-9]*$/i', 
     1398                    array('media_exclusion','string','/\.(phps?|pht(ml)?|phl|s?html?|js|htaccess)[0-9]*$/i', 
    13991399                    'File name exclusion pattern in media manager. (PCRE value)'), 
    14001400                    array('media_img_m_size','integer',448, 
  • inc/dbschema/upgrade.php

    r3261 r3267  
    552552                    @file_put_contents($f,'Require all denied'."\n".'Deny from all'."\n"); 
    553553               } 
     554 
     555               # Update flie exclusion upload regex 
     556               $strReq = 'UPDATE '.$core->prefix.'setting '. 
     557                         " SET setting_value = '/\\.(phps?|pht(ml)?|phl|s?html?|js|htaccess)[0-9]*\$/i' ". 
     558                         " WHERE setting_id = 'media_exclusion' ". 
     559                         " AND setting_ns = 'system' ". 
     560                         " AND (setting_value = '/\\.php[0-9]*\$/i' ". 
     561                         "   OR setting_value = '/\\.php\$/i') ". 
     562                         "    OR setting_value = '/\\.(phps?|pht(ml)?|phl)[0-9]*\$/i' ". 
     563                         "    OR setting_value = '/\\.(phps?|pht(ml)?|phl|s?html?|js)[0-9]*\$/i'"; 
     564               $core->con->execute($strReq); 
    554565          } 
    555566 
Note: See TracChangeset for help on using the changeset viewer.

Sites map