diff --git a/index.php b/index.php index 10ab357..7a793c0 100644 --- a/index.php +++ b/index.php @@ -90,7 +90,7 @@ if($_GET['do'] == 'list') { rmrf($file); } exit; -} elseif ($_POST['do'] == 'mkdir' && $allow_create_folder && $allow_upload) { +} elseif ($_POST['do'] == 'mkdir' && $allow_create_folder) { // don't allow actions outside root. we also filter out slashes to catch args like './../outside' $dir = $_POST['name']; $dir = str_replace('/', '', $dir); @@ -431,7 +431,7 @@ $(function(){
- +