mirror of
https://github.com/itflow-org/itflow
synced 2026-03-21 13:05:39 +00:00
Add index.php files to upload directories to prevent file traversal
This commit is contained in:
1
post.php
1
post.php
@@ -1015,6 +1015,7 @@ if(isset($_POST['add_client'])){
|
|||||||
|
|
||||||
if(!file_exists("uploads/clients/$session_company_id/$client_id")) {
|
if(!file_exists("uploads/clients/$session_company_id/$client_id")) {
|
||||||
mkdir("uploads/clients/$session_company_id/$client_id");
|
mkdir("uploads/clients/$session_company_id/$client_id");
|
||||||
|
file_put_contents("uploads/clients/$session_company_id/$client_id/index.php", "");
|
||||||
}
|
}
|
||||||
|
|
||||||
//Add Location
|
//Add Location
|
||||||
|
|||||||
@@ -482,9 +482,13 @@ if(isset($_POST['add_company_settings'])){
|
|||||||
$config_aes_key = keygen();
|
$config_aes_key = keygen();
|
||||||
|
|
||||||
mkdir_missing("uploads/clients/$company_id");
|
mkdir_missing("uploads/clients/$company_id");
|
||||||
|
file_put_contents("uploads/clients/$company_id/index.php", "");
|
||||||
mkdir_missing("uploads/expenses/$company_id");
|
mkdir_missing("uploads/expenses/$company_id");
|
||||||
|
file_put_contents("uploads/expenses/$company_id/index.php", "");
|
||||||
mkdir_missing("uploads/settings/$company_id");
|
mkdir_missing("uploads/settings/$company_id");
|
||||||
|
file_put_contents("uploads/settings/$company_id/index.php", "");
|
||||||
mkdir_missing("uploads/tmp/$company_id");
|
mkdir_missing("uploads/tmp/$company_id");
|
||||||
|
file_put_contents("uploads/tmp/$company_id/index.php", "");
|
||||||
|
|
||||||
//Check to see if a file is attached
|
//Check to see if a file is attached
|
||||||
if($_FILES['file']['tmp_name'] != ''){
|
if($_FILES['file']['tmp_name'] != ''){
|
||||||
|
|||||||
Reference in New Issue
Block a user