]> jfr.im git - uguu.git/commitdiff
strip some tags v1.5.2
authornokonoko <redacted>
Sat, 29 Jan 2022 20:42:49 +0000 (21:42 +0100)
committernokonoko <redacted>
Sat, 29 Jan 2022 20:42:49 +0000 (21:42 +0100)
dist.json
package.json
static/php/includes/Core.namespace.php
static/php/includes/Upload.class.php

index e0c4b20f866e160c835e6997b65d98d19ddb6cb2..5ab37cb1a38f3c6502a94023762b24e09c990004 100644 (file)
--- a/dist.json
+++ b/dist.json
@@ -3,7 +3,7 @@
     "allowErrors": false
   },
   "dest": "dist",
-  "pkgVersion": "1.5.1",
+  "pkgVersion": "1.5.2",
   "banners": [
     "banners/malware_scans.swig",
     "banners/donations.swig"
index c3ce9501ec67da826711cd404965bd8a5e19c9e8..5eafc445d03507bfa1cfe57e0d11c597f38f61f8 100644 (file)
@@ -1,6 +1,6 @@
 {
   "name": "uguu",
-  "version": "1.5.1",
+  "version": "1.5.2",
   "description": "Kawaii file host",
   "homepage": "https://uguu.se/",
   "repository": {
index b5665332402832dfa7b7b822dc35c23ac1b2cc78..1626ff2e006b55d6ec42f16a6a6487a2b078be68 100644 (file)
@@ -347,7 +347,7 @@ namespace Core {
                     'VALUES (:hash, :orig, :name, :size, :date, :ip)'
                 );
                 $q->bindValue(':hash', Upload::$SHA1, PDO::PARAM_STR);
-                $q->bindValue(':orig', strip_tags(Upload::$FILE_NAME), PDO::PARAM_STR);
+                $q->bindValue(':orig', Upload::$FILE_NAME, PDO::PARAM_STR);
                 $q->bindValue(':name', Upload::$NEW_NAME_FULL, PDO::PARAM_STR);
                 $q->bindValue(':size', Upload::$FILE_SIZE, PDO::PARAM_INT);
                 $q->bindValue(':date', time(), PDO::PARAM_STR);
index c81b67197555252914f69e6bbaf68255c92ce989..9fb5e0fd5be58943bf71f47690b55e3170d16858 100644 (file)
@@ -45,7 +45,7 @@ class Upload
         $files = self::diverseArray($files);
 
         foreach ($files as $file) {
-            self::$FILE_NAME = $file['name'];
+            self::$FILE_NAME = strip_tags($file['name']);
             self::$FILE_SIZE = $file['size'];
             self::$TEMP_FILE = $file['tmp_name'];
             self::$SHA1 = sha1_file(self::$TEMP_FILE);