Merge remote-tracking branch 'marc1706/master'

This commit is contained in:
Marc Alexander
2011-04-24 21:53:15 +02:00

View File

@@ -112,7 +112,8 @@ class portal_upload
$cur_path = str_replace($mod_dir . '/', '', $cur_path); $cur_path = str_replace($mod_dir . '/', '', $cur_path);
$cut_pos = strpos($cur_path, '/'); $cut_pos = strpos($cur_path, '/');
if(!in_array(substr($cur_path, 0, $cut_pos), array('portal', 'language', 'styles'))) // Only allow files in adm, language, portal and styles folder
if(!in_array(substr($cur_path, 0, $cut_pos), array('adm', 'language', 'portal', 'styles')))
{ {
$file->remove(); $file->remove();
$this->directory_delete($mod_dir); $this->directory_delete($mod_dir);