From d18fd04ce9d8a1f4ee756f54052eff36ad28cca7 Mon Sep 17 00:00:00 2001 From: John Campbell Date: Thu, 12 Apr 2018 14:21:26 -0400 Subject: [PATCH] Removing unexpected behavior... HT: Mark Szabo --- index.php | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/index.php b/index.php index 10ab357..7a793c0 100644 --- a/index.php +++ b/index.php @@ -90,7 +90,7 @@ if($_GET['do'] == 'list') { rmrf($file); } exit; -} elseif ($_POST['do'] == 'mkdir' && $allow_create_folder && $allow_upload) { +} elseif ($_POST['do'] == 'mkdir' && $allow_create_folder) { // don't allow actions outside root. we also filter out slashes to catch args like './../outside' $dir = $_POST['name']; $dir = str_replace('/', '', $dir); @@ -431,7 +431,7 @@ $(function(){
- +