Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c2a4a39ea0 | ||
|
|
b8759e4acd | ||
|
|
e6a3df6f08 | ||
|
|
617dfbf0e2 | ||
|
|
e4c9bf5ba4 | ||
|
|
910091b6c6 | ||
|
|
92b8ce3a89 | ||
|
|
8a276fc073 | ||
|
|
baa2e890ba | ||
|
|
a9f4aee93f | ||
|
|
144926774d | ||
|
|
435da08a02 | ||
|
|
945c060b67 | ||
|
|
83fd4bf68a | ||
|
|
f11c4531e9 | ||
|
|
f36c24e5d0 | ||
|
|
23a91b346d |
@@ -2,4 +2,8 @@
|
||||
define('G5_IS_ADMIN', true);
|
||||
include_once ('../common.php');
|
||||
include_once(G5_ADMIN_PATH.'/admin.lib.php');
|
||||
|
||||
if( isset($token) ){
|
||||
$token = @htmlspecialchars(strip_tags($token), ENT_QUOTES);
|
||||
}
|
||||
?>
|
||||
@@ -35,6 +35,14 @@ if ($file = $_POST['bo_include_tail']) {
|
||||
$_POST['bo_include_tail'] = $file;
|
||||
}
|
||||
|
||||
if(!is_include_path_check($_POST['bo_include_head'])) {
|
||||
alert('/data/file/ 또는 /data/editor/ 포함된 문자를 상단 파일 경로에 포함시킬수 없습니다.');
|
||||
}
|
||||
|
||||
if(!is_include_path_check($_POST['bo_include_tail'])) {
|
||||
alert('/data/file/ 또는 /data/editor/ 포함된 문자를 하단 파일 경로에 포함시킬수 없습니다.');
|
||||
}
|
||||
|
||||
$board_path = G5_DATA_PATH.'/file/'.$bo_table;
|
||||
|
||||
// 게시판 디렉토리 생성
|
||||
|
||||
+1
-1
@@ -63,7 +63,7 @@ $colspan = 15;
|
||||
|
||||
<label for="sfl" class="sound_only">검색대상</label>
|
||||
<select name="sfl" id="sfl">
|
||||
<option value="bo_table"<?php echo get_selected($_GET['sfl'], "bo_subject", true); ?>>TABLE</option>
|
||||
<option value="bo_table"<?php echo get_selected($_GET['sfl'], "bo_table", true); ?>>TABLE</option>
|
||||
<option value="bo_subject"<?php echo get_selected($_GET['sfl'], "bo_subject"); ?>>제목</option>
|
||||
<option value="a.gr_id"<?php echo get_selected($_GET['sfl'], "a.gr_id"); ?>>그룹ID</option>
|
||||
</select>
|
||||
|
||||
@@ -18,6 +18,18 @@ check_admin_token();
|
||||
if ($co_himg_del) @unlink(G5_DATA_PATH."/content/{$co_id}_h");
|
||||
if ($co_timg_del) @unlink(G5_DATA_PATH."/content/{$co_id}_t");
|
||||
|
||||
$error_msg = '';
|
||||
|
||||
if( $co_include_head && ! is_include_path_check($co_include_head) ){
|
||||
$co_include_head = '';
|
||||
$error_msg = '/data/file/ 또는 /data/editor/ 포함된 문자를 상단 파일 경로에 포함시킬수 없습니다.';
|
||||
}
|
||||
|
||||
if( $co_include_tail && ! is_include_path_check($co_include_tail) ){
|
||||
$co_include_tail = '';
|
||||
$error_msg = '/data/file/ 또는 /data/editor/ 포함된 문자를 하단 파일 경로에 포함시킬수 없습니다.';
|
||||
}
|
||||
|
||||
$sql_common = " co_include_head = '$co_include_head',
|
||||
co_include_tail = '$co_include_tail',
|
||||
co_html = '$co_html',
|
||||
@@ -74,7 +86,11 @@ if ($w == "" || $w == "u")
|
||||
@chmod($dest_path, G5_FILE_PERMISSION);
|
||||
}
|
||||
|
||||
goto_url("./contentform.php?w=u&co_id=$co_id");
|
||||
if( $error_msg ){
|
||||
alert($error_msg, "./contentform.php?w=u&co_id=$co_id");
|
||||
} else {
|
||||
goto_url("./contentform.php?w=u&co_id=$co_id");
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
|
||||
@@ -311,6 +311,7 @@ tfoot td {font-weight:bold;text-align:center}
|
||||
#menu_frm #menu_result {margin:20px 0}
|
||||
|
||||
#menulist .sub_menu_class {padding-left:25px;background:url('../img/sub_menu_ico.gif') 5px 15px no-repeat}
|
||||
.exist_menu_link {font-weight:bold;color:red}
|
||||
|
||||
/* 회원관리 목록 */
|
||||
.mb_leave_msg {color:#b6b6b6}
|
||||
|
||||
+47
-3
@@ -43,13 +43,57 @@ $(function() {
|
||||
"./menu_form_search.php"
|
||||
);
|
||||
|
||||
$("#me_type").on("change", function() {
|
||||
var type = $(this).val();
|
||||
function link_checks_all_chage(){
|
||||
|
||||
var $links = $(opener.document).find("#menulist input[name='me_link[]']"),
|
||||
$o_link = $(".td_mngsmall input[name='link[]']"),
|
||||
hrefs = [],
|
||||
menu_exist = false;
|
||||
|
||||
if( $links.length ){
|
||||
$links.each(function( index ) {
|
||||
hrefs.push( $(this).val() );
|
||||
});
|
||||
|
||||
$o_link.each(function( index ) {
|
||||
if( $.inArray( $(this).val(), hrefs ) != -1 ){
|
||||
$(this).closest("tr").find("td:eq( 0 )").addClass("exist_menu_link");
|
||||
menu_exist = true;
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
if( menu_exist ){
|
||||
$(".menu_exists_tip").show();
|
||||
} else {
|
||||
$(".menu_exists_tip").hide();
|
||||
}
|
||||
}
|
||||
|
||||
function menu_result_change( type ){
|
||||
|
||||
var dfd = new $.Deferred();
|
||||
|
||||
$("#menu_result").empty().load(
|
||||
"./menu_form_search.php",
|
||||
{ type : type }
|
||||
{ type : type },
|
||||
function(){
|
||||
dfd.resolve('Finished');
|
||||
}
|
||||
);
|
||||
|
||||
return dfd.promise();
|
||||
}
|
||||
|
||||
$("#me_type").on("change", function() {
|
||||
var type = $(this).val();
|
||||
|
||||
var promise = menu_result_change( type );
|
||||
|
||||
promise.done(function(message) {
|
||||
link_checks_all_chage(type);
|
||||
});
|
||||
|
||||
});
|
||||
|
||||
$(document).on("click", "#add_manual", function() {
|
||||
|
||||
@@ -11,7 +11,7 @@ switch($type) {
|
||||
order by gr_order, gr_id ";
|
||||
break;
|
||||
case 'board':
|
||||
$sql = " select bo_table as id, bo_subject as subject
|
||||
$sql = " select bo_table as id, bo_subject as subject, gr_id
|
||||
from {$g5['board_table']}
|
||||
order by bo_order, bo_table ";
|
||||
break;
|
||||
@@ -32,13 +32,18 @@ if($sql) {
|
||||
|
||||
for($i=0; $row=sql_fetch_array($result); $i++) {
|
||||
if($i == 0) {
|
||||
|
||||
$bbs_subject_title = ($type == 'board') ? '게시판제목' : '제목';
|
||||
?>
|
||||
|
||||
<div class="tbl_head01 tbl_wrap">
|
||||
<table>
|
||||
<thead>
|
||||
<tr>
|
||||
<th scope="col">제목</th>
|
||||
<th scope="col"><?php echo $bbs_subject_title; ?></th>
|
||||
<?php if($type == 'board'){ ?>
|
||||
<th scope="col">게시판 그룹</th>
|
||||
<?php } ?>
|
||||
<th scope="col">선택</th>
|
||||
</tr>
|
||||
</thead>
|
||||
@@ -63,6 +68,12 @@ if($sql) {
|
||||
|
||||
<tr>
|
||||
<td><?php echo $row['subject']; ?></td>
|
||||
<?php
|
||||
if($type == 'board'){
|
||||
$group = get_call_func_cache('get_group', array($row['gr_id']));
|
||||
?>
|
||||
<td><?php echo $group['gr_subject']; ?></td>
|
||||
<?php } ?>
|
||||
<td class="td_mngsmall">
|
||||
<input type="hidden" name="subject[]" value="<?php echo preg_replace('/[\'\"]/', '', $row['subject']); ?>">
|
||||
<input type="hidden" name="link[]" value="<?php echo $link; ?>">
|
||||
@@ -76,6 +87,10 @@ if($sql) {
|
||||
</table>
|
||||
</div>
|
||||
|
||||
<div class="local_desc01 menu_exists_tip" style="display:none">
|
||||
<p>* <strong>빨간색</strong>의 제목은 이미 메뉴에 연결되어 경우 표시됩니다.</p>
|
||||
</div>
|
||||
|
||||
<div class="btn_win02 btn_win">
|
||||
<button type="button" class="btn_cancel" onclick="window.close();">창닫기</button>
|
||||
</div>
|
||||
|
||||
@@ -8,6 +8,18 @@ auth_check($auth[$sub_menu], 'w');
|
||||
|
||||
check_admin_token();
|
||||
|
||||
$error_msg = '';
|
||||
|
||||
if( $qa_include_head && ! is_include_path_check($qa_include_head) ){
|
||||
$qa_include_head = '';
|
||||
$error_msg = '/data/file/ 또는 /data/editor/ 포함된 문자를 상단 파일 경로에 포함시킬수 없습니다.';
|
||||
}
|
||||
|
||||
if( $qa_include_tail && ! is_include_path_check($qa_include_tail) ){
|
||||
$qa_include_tail = '';
|
||||
$error_msg = '/data/file/ 또는 /data/editor/ 포함된 문자를 하단 파일 경로에 포함시킬수 없습니다.';
|
||||
}
|
||||
|
||||
$sql = " update {$g5['qa_config_table']}
|
||||
set qa_title = '{$_POST['qa_title']}',
|
||||
qa_category = '{$_POST['qa_category']}',
|
||||
@@ -29,8 +41,8 @@ $sql = " update {$g5['qa_config_table']}
|
||||
qa_image_width = '{$_POST['qa_image_width']}',
|
||||
qa_upload_size = '{$_POST['qa_upload_size']}',
|
||||
qa_insert_content = '{$_POST['qa_insert_content']}',
|
||||
qa_include_head = '{$_POST['qa_include_head']}',
|
||||
qa_include_tail = '{$_POST['qa_include_tail']}',
|
||||
qa_include_head = '{$qa_include_head}',
|
||||
qa_include_tail = '{$qa_include_tail}',
|
||||
qa_content_head = '{$_POST['qa_content_head']}',
|
||||
qa_content_tail = '{$_POST['qa_content_tail']}',
|
||||
qa_mobile_content_head = '{$_POST['qa_mobile_content_head']}',
|
||||
@@ -47,5 +59,9 @@ $sql = " update {$g5['qa_config_table']}
|
||||
qa_5 = '{$_POST['qa_5']}' ";
|
||||
sql_query($sql);
|
||||
|
||||
goto_url('./qa_config.php');
|
||||
if($error_msg){
|
||||
alert($error_msg, './qa_config.php');
|
||||
} else {
|
||||
goto_url('./qa_config.php');
|
||||
}
|
||||
?>
|
||||
@@ -12,5 +12,11 @@ if (!strstr($_SERVER['SCRIPT_NAME'], 'install.php')) {
|
||||
//$sms5 = sql_fetch("select * from ".$g5['sms5_config_table'] );
|
||||
}
|
||||
|
||||
$sv = isset($_REQUEST['sv']) ? get_search_string($_REQUEST['sv']) : '';
|
||||
|
||||
if( isset($token) ){
|
||||
$token = @htmlspecialchars(strip_tags($token), ENT_QUOTES);
|
||||
}
|
||||
|
||||
add_stylesheet('<link rel="stylesheet" href="'.G5_SMS5_ADMIN_URL.'/css/sms5.css">', 0);
|
||||
?>
|
||||
@@ -71,6 +71,7 @@ for ($i=0; $row=sql_fetch_array($result); $i++) {
|
||||
</tr>
|
||||
|
||||
<?php
|
||||
$i++;
|
||||
}
|
||||
} else {
|
||||
echo '<tr><td colspan="'.$colspan.'" class="empty_table">자료가 없습니다.</td></tr>';
|
||||
|
||||
@@ -72,6 +72,7 @@ for ($i=0; $row=sql_fetch_array($result); $i++) {
|
||||
</tr>
|
||||
|
||||
<?php
|
||||
$i++;
|
||||
}
|
||||
|
||||
|
||||
|
||||
@@ -44,7 +44,7 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'">처음</a>'; //페이지 처
|
||||
<?php
|
||||
$sql_common = " from {$g5['visit_table']} ";
|
||||
if ($sfl) {
|
||||
if($sst=='vi_ip' || $sst=='vi_date'){
|
||||
if($sfl=='vi_ip' || $sfl=='vi_date'){
|
||||
$sql_search = " where $sfl like '$stx%' ";
|
||||
}else{
|
||||
$sql_search = " where $sfl like '%$stx%' ";
|
||||
|
||||
+5
-1
@@ -7,7 +7,11 @@ if (G5_IS_MOBILE) {
|
||||
include_once(G5_BBS_PATH.'/_head.php');
|
||||
echo stripslashes($board['bo_mobile_content_head']);
|
||||
} else {
|
||||
@include ($board['bo_include_head']);
|
||||
if(is_include_path_check($board['bo_include_head'])) { //파일경로 체크
|
||||
@include ($board['bo_include_head']);
|
||||
} else { //파일경로가 올바르지 않으면 기본파일을 가져옴
|
||||
include_once(G5_BBS_PATH.'/_head.php');
|
||||
}
|
||||
echo stripslashes($board['bo_content_head']);
|
||||
}
|
||||
?>
|
||||
+5
-1
@@ -8,6 +8,10 @@ if (G5_IS_MOBILE) {
|
||||
include_once(G5_BBS_PATH.'/_tail.php');
|
||||
} else {
|
||||
echo stripslashes($board['bo_content_tail']);
|
||||
@include ($board['bo_include_tail']);
|
||||
if(is_include_path_check($board['bo_include_tail'])) { //파일경로 체크
|
||||
@include ($board['bo_include_tail']);
|
||||
} else { //파일경로가 올바르지 않으면 기본파일을 가져옴
|
||||
include_once(G5_BBS_PATH.'/_tail.php');
|
||||
}
|
||||
}
|
||||
?>
|
||||
+2
-2
@@ -19,7 +19,7 @@ if (!$co['co_id'])
|
||||
|
||||
$g5['title'] = $co['co_subject'];
|
||||
|
||||
if ($co['co_include_head'])
|
||||
if (is_include_path_check($co['co_include_head']))
|
||||
@include_once($co['co_include_head']);
|
||||
else
|
||||
include_once('./_head.php');
|
||||
@@ -85,7 +85,7 @@ if(is_file($skin_file)) {
|
||||
echo '<p>'.str_replace(G5_PATH.'/', '', $skin_file).'이 존재하지 않습니다.</p>';
|
||||
}
|
||||
|
||||
if ($co['co_include_tail'])
|
||||
if (is_include_path_check($co['co_include_tail']))
|
||||
@include_once($co['co_include_tail']);
|
||||
else
|
||||
include_once('./_tail.php');
|
||||
|
||||
+1
-1
@@ -9,7 +9,7 @@ if (G5_IS_MOBILE) {
|
||||
include_once('./_head.php');
|
||||
echo conv_content($qaconfig['qa_mobile_content_head'], 1);
|
||||
} else {
|
||||
if($qaconfig['qa_include_head'])
|
||||
if(is_include_path_check($qaconfig['qa_include_head']))
|
||||
@include ($qaconfig['qa_include_head']);
|
||||
else
|
||||
include ('./_head.php');
|
||||
|
||||
+1
-1
@@ -7,7 +7,7 @@ if (G5_IS_MOBILE) {
|
||||
include_once('./_tail.php');
|
||||
} else {
|
||||
echo conv_content($qaconfig['qa_content_tail'], 1);
|
||||
if($qaconfig['qa_include_tail'])
|
||||
if(is_include_path_check($qaconfig['qa_include_tail']))
|
||||
@include ($qaconfig['qa_include_tail']);
|
||||
else
|
||||
include ('./_tail.php');
|
||||
|
||||
+4
-3
@@ -32,10 +32,11 @@ function g5_path()
|
||||
$result['path'] = str_replace('\\', '/', dirname(__FILE__));
|
||||
$tilde_remove = preg_replace('/^\/\~[^\/]+(.*)$/', '$1', $_SERVER['SCRIPT_NAME']);
|
||||
$document_root = str_replace($tilde_remove, '', $_SERVER['SCRIPT_FILENAME']);
|
||||
$root = str_replace($document_root, '', $result['path']);
|
||||
$pattern = '/' . preg_quote($document_root, '/') . '/i';
|
||||
$root = preg_replace($pattern, '', $result['path']);
|
||||
$port = $_SERVER['SERVER_PORT'] != 80 ? ':'.$_SERVER['SERVER_PORT'] : '';
|
||||
$http = 'http' . ((isset($_SERVER['HTTPS']) && $_SERVER['HTTPS']=='on') ? 's' : '') . '://';
|
||||
$user = str_replace(str_replace($document_root, '', $_SERVER['SCRIPT_FILENAME']), '', $_SERVER['SCRIPT_NAME']);
|
||||
$user = str_replace(preg_replace($pattern, '', $_SERVER['SCRIPT_FILENAME']), '', $_SERVER['SCRIPT_NAME']);
|
||||
$host = isset($_SERVER['HTTP_HOST']) ? $_SERVER['HTTP_HOST'] : $_SERVER['SERVER_NAME'];
|
||||
if(isset($_SERVER['HTTP_HOST']) && preg_match('/:[0-9]+$/', $host))
|
||||
$host = preg_replace('/:[0-9]+$/', '', $host);
|
||||
@@ -370,7 +371,7 @@ if ($_SESSION['ss_mb_id']) { // 로그인중이라면
|
||||
$key = md5($_SERVER['SERVER_ADDR'] . $_SERVER['REMOTE_ADDR'] . $_SERVER['HTTP_USER_AGENT'] . $row['mb_password']);
|
||||
// 쿠키에 저장된 키와 같다면
|
||||
$tmp_key = get_cookie('ck_auto');
|
||||
if ($tmp_key == $key && $tmp_key) {
|
||||
if ($tmp_key === $key && $tmp_key) {
|
||||
// 차단, 탈퇴가 아니고 메일인증이 사용이면서 인증을 받았다면
|
||||
if ($row['mb_intercept_date'] == '' &&
|
||||
$row['mb_leave_date'] == '' &&
|
||||
|
||||
+1
-1
@@ -5,7 +5,7 @@
|
||||
********************/
|
||||
|
||||
define('G5_VERSION', '그누보드5');
|
||||
define('G5_GNUBOARD_VER', '5.2.6');
|
||||
define('G5_GNUBOARD_VER', '5.2.8');
|
||||
|
||||
// 이 상수가 정의되지 않으면 각각의 개별 페이지는 별도로 실행될 수 없음
|
||||
define('_GNUBOARD_', true);
|
||||
|
||||
+1
-1
@@ -45,7 +45,7 @@ if (G5_IS_MOBILE) {
|
||||
echo '<meta name="format-detection" content="telephone=no">'.PHP_EOL;
|
||||
} else {
|
||||
echo '<meta http-equiv="imagetoolbar" content="no">'.PHP_EOL;
|
||||
echo '<meta http-equiv="X-UA-Compatible" content="IE=10,chrome=1">'.PHP_EOL;
|
||||
echo '<meta http-equiv="X-UA-Compatible" content="IE=Edge">'.PHP_EOL;
|
||||
}
|
||||
|
||||
if($config['cf_add_meta'])
|
||||
|
||||
@@ -1,4 +1,6 @@
|
||||
<?php
|
||||
@header('Content-Type: text/html; charset=utf-8');
|
||||
@header('X-Robots-Tag: noindex');
|
||||
include_once ('../config.php');
|
||||
$title = G5_VERSION." 라이센스 확인 1/3";
|
||||
include_once ('./install.inc.php');
|
||||
|
||||
@@ -5,6 +5,8 @@ header('Last-Modified: ' . $gmnow);
|
||||
header('Cache-Control: no-store, no-cache, must-revalidate'); // HTTP/1.1
|
||||
header('Cache-Control: pre-check=0, post-check=0, max-age=0'); // HTTP/1.1
|
||||
header('Pragma: no-cache'); // HTTP/1.0
|
||||
@header('Content-Type: text/html; charset=utf-8');
|
||||
@header('X-Robots-Tag: noindex');
|
||||
|
||||
include_once ('../config.php');
|
||||
$title = G5_VERSION." 초기환경설정 2/3";
|
||||
|
||||
@@ -6,6 +6,8 @@ header('Last-Modified: ' . $gmnow);
|
||||
header('Cache-Control: no-store, no-cache, must-revalidate'); // HTTP/1.1
|
||||
header('Cache-Control: pre-check=0, post-check=0, max-age=0'); // HTTP/1.1
|
||||
header('Pragma: no-cache'); // HTTP/1.0
|
||||
@header('Content-Type: text/html; charset=utf-8');
|
||||
@header('X-Robots-Tag: noindex');
|
||||
|
||||
include_once ('../config.php');
|
||||
include_once ('../lib/common.lib.php');
|
||||
|
||||
+70
-2
@@ -628,7 +628,7 @@ function get_sql_search($search_ca_name, $search_field, $search_text, $search_op
|
||||
|
||||
// SQL Injection 방지
|
||||
// 필드값에 a-z A-Z 0-9 _ , | 이외의 값이 있다면 검색필드를 wr_subject 로 설정한다.
|
||||
$field[$k] = preg_match("/^[\w\,\|]+$/", $field[$k]) ? $field[$k] : "wr_subject";
|
||||
$field[$k] = preg_match("/^[\w\,\|]+$/", $field[$k]) ? strtolower($field[$k]) : "wr_subject";
|
||||
|
||||
$str .= $op2;
|
||||
switch ($field[$k]) {
|
||||
@@ -3197,7 +3197,7 @@ class str_encrypt
|
||||
function __construct($salt='')
|
||||
{
|
||||
if(!$salt)
|
||||
$this->salt = md5(G5_MYSQL_PASSWORD);
|
||||
$this->salt = md5(preg_replace('/[^0-9A-Za-z]/', substr(G5_MYSQL_USER, -1), G5_MYSQL_PASSWORD));
|
||||
else
|
||||
$this->salt = $salt;
|
||||
|
||||
@@ -3259,4 +3259,72 @@ function check_write_token($bo_table)
|
||||
|
||||
return true;
|
||||
}
|
||||
|
||||
function get_call_func_cache($func, $args=array()){
|
||||
|
||||
static $cache = array();
|
||||
|
||||
$key = md5(serialize($args));
|
||||
|
||||
if( isset($cache[$func]) && isset($cache[$func][$key]) ){
|
||||
return $cache[$func][$key];
|
||||
}
|
||||
|
||||
$result = null;
|
||||
|
||||
try{
|
||||
$cache[$func][$key] = $result = call_user_func_array($func, $args);
|
||||
} catch (Exception $e) {
|
||||
return null;
|
||||
}
|
||||
|
||||
return $result;
|
||||
}
|
||||
|
||||
// include 하는 경로에 data file 경로가 포함되어 있는지 체크합니다.
|
||||
function is_include_path_check($path='')
|
||||
{
|
||||
if( $path ){
|
||||
try {
|
||||
// whether $path is unix or not
|
||||
$unipath = strlen($path)==0 || $path{0}!='/';
|
||||
$unc = substr($path,0,2)=='\\\\'?true:false;
|
||||
// attempts to detect if path is relative in which case, add cwd
|
||||
if(strpos($path,':') === false && $unipath && !$unc){
|
||||
$path=getcwd().DIRECTORY_SEPARATOR.$path;
|
||||
if($path{0}=='/'){
|
||||
$unipath = false;
|
||||
}
|
||||
}
|
||||
|
||||
// resolve path parts (single dot, double dot and double delimiters)
|
||||
$path = str_replace(array('/', '\\'), DIRECTORY_SEPARATOR, $path);
|
||||
$parts = array_filter(explode(DIRECTORY_SEPARATOR, $path), 'strlen');
|
||||
$absolutes = array();
|
||||
foreach ($parts as $part) {
|
||||
if ('.' == $part){
|
||||
continue;
|
||||
}
|
||||
if ('..' == $part) {
|
||||
array_pop($absolutes);
|
||||
} else {
|
||||
$absolutes[] = $part;
|
||||
}
|
||||
}
|
||||
$path = implode(DIRECTORY_SEPARATOR, $absolutes);
|
||||
// resolve any symlinks
|
||||
// put initial separator that could have been lost
|
||||
$path = !$unipath ? '/'.$path : $path;
|
||||
$path = $unc ? '\\\\'.$path : $path;
|
||||
} catch (Exception $e) {
|
||||
//echo 'Caught exception: ', $e->getMessage(), "\n";
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
if( !$path || preg_match('/\/data\/(file|editor)\/[A-Za-z0-9_]{1,20}\//', $path) ){
|
||||
return false;
|
||||
}
|
||||
return true;
|
||||
}
|
||||
?>
|
||||
+50
-18
@@ -4,7 +4,7 @@ if (!defined('_GNUBOARD_')) exit;
|
||||
@ini_set('memory_limit', '-1');
|
||||
|
||||
// 게시글리스트 썸네일 생성
|
||||
function get_list_thumbnail($bo_table, $wr_id, $thumb_width, $thumb_height, $is_create=false, $is_crop=true, $crop_mode='center', $is_sharpen=false, $um_value='80/0.5/3')
|
||||
function get_list_thumbnail($bo_table, $wr_id, $thumb_width, $thumb_height, $is_create=false, $is_crop=false, $crop_mode='center', $is_sharpen=false, $um_value='80/0.5/3')
|
||||
{
|
||||
global $g5, $config;
|
||||
$filename = $alt = "";
|
||||
@@ -238,10 +238,10 @@ function thumbnail($filename, $source_path, $target_path, $thumb_width, $thumb_h
|
||||
$degree = 0;
|
||||
|
||||
if ($size[2] == 1) {
|
||||
$src = imagecreatefromgif($source_file);
|
||||
$src_transparency = imagecolortransparent($src);
|
||||
$src = @imagecreatefromgif($source_file);
|
||||
$src_transparency = @imagecolortransparent($src);
|
||||
} else if ($size[2] == 2) {
|
||||
$src = imagecreatefromjpeg($source_file);
|
||||
$src = @imagecreatefromjpeg($source_file);
|
||||
|
||||
if(function_exists('exif_read_data')) {
|
||||
// exif 정보를 기준으로 회전각도 구함
|
||||
@@ -273,8 +273,8 @@ function thumbnail($filename, $source_path, $target_path, $thumb_width, $thumb_h
|
||||
}
|
||||
}
|
||||
} else if ($size[2] == 3) {
|
||||
$src = imagecreatefrompng($source_file);
|
||||
imagealphablending($src, true);
|
||||
$src = @imagecreatefrompng($source_file);
|
||||
@imagealphablending($src, true);
|
||||
} else {
|
||||
return;
|
||||
}
|
||||
@@ -330,20 +330,52 @@ function thumbnail($filename, $source_path, $target_path, $thumb_width, $thumb_h
|
||||
}
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
$dst = imagecreatetruecolor($dst_w, $dst_h);
|
||||
$dst = imagecreatetruecolor($dst_w, $dst_h);
|
||||
|
||||
if($size[2] == 3) {
|
||||
imagealphablending($dst, false);
|
||||
imagesavealpha($dst, true);
|
||||
} else if($size[2] == 1) {
|
||||
$palletsize = imagecolorstotal($src);
|
||||
if($src_transparency >= 0 && $src_transparency < $palletsize) {
|
||||
$transparent_color = imagecolorsforindex($src, $src_transparency);
|
||||
$current_transparent = imagecolorallocate($dst, $transparent_color['red'], $transparent_color['green'], $transparent_color['blue']);
|
||||
imagefill($dst, 0, 0, $current_transparent);
|
||||
imagecolortransparent($dst, $current_transparent);
|
||||
if($size[2] == 3) {
|
||||
imagealphablending($dst, false);
|
||||
imagesavealpha($dst, true);
|
||||
} else if($size[2] == 1) {
|
||||
$palletsize = imagecolorstotal($src);
|
||||
if($src_transparency >= 0 && $src_transparency < $palletsize) {
|
||||
$transparent_color = imagecolorsforindex($src, $src_transparency);
|
||||
$current_transparent = imagecolorallocate($dst, $transparent_color['red'], $transparent_color['green'], $transparent_color['blue']);
|
||||
imagefill($dst, 0, 0, $current_transparent);
|
||||
imagecolortransparent($dst, $current_transparent);
|
||||
}
|
||||
}
|
||||
} else { // 비율에 맞게 생성
|
||||
$dst = imagecreatetruecolor($dst_w, $dst_h);
|
||||
$bgcolor = imagecolorallocate($dst, 255, 255, 255); // 배경색
|
||||
|
||||
if($src_w > $src_h) {
|
||||
$tmp_h = round(($dst_w * $src_h) / $src_w);
|
||||
$dst_y = round(($dst_h - $tmp_h) / 2);
|
||||
$dst_h = $tmp_h;
|
||||
} else {
|
||||
$tmp_w = round(($dst_h * $src_w) / $src_h);
|
||||
$dst_x = round(($dst_w - $tmp_w) / 2);
|
||||
$dst_w = $tmp_w;
|
||||
}
|
||||
|
||||
if($size[2] == 3) {
|
||||
$bgcolor = imagecolorallocatealpha($dst, 0, 0, 0, 127);
|
||||
imagefill($dst, 0, 0, $bgcolor);
|
||||
imagealphablending($dst, false);
|
||||
imagesavealpha($dst, true);
|
||||
} else if($size[2] == 1) {
|
||||
$palletsize = imagecolorstotal($src);
|
||||
if($src_transparency >= 0 && $src_transparency < $palletsize) {
|
||||
$transparent_color = imagecolorsforindex($src, $src_transparency);
|
||||
$current_transparent = imagecolorallocate($dst, $transparent_color['red'], $transparent_color['green'], $transparent_color['blue']);
|
||||
imagefill($dst, 0, 0, $current_transparent);
|
||||
imagecolortransparent($dst, $current_transparent);
|
||||
} else {
|
||||
imagefill($dst, 0, 0, $bgcolor);
|
||||
}
|
||||
} else {
|
||||
imagefill($dst, 0, 0, $bgcolor);
|
||||
}
|
||||
}
|
||||
} else {
|
||||
|
||||
@@ -5,9 +5,9 @@ if(!function_exists('ft_nonce_is_valid')){
|
||||
include_once('../editor.lib.php');
|
||||
}
|
||||
|
||||
$filesrc = isset($_POST["filesrc"]) ? $_POST["filesrc"] : '';
|
||||
$filesrc = isset($_POST["filesrc"]) ? preg_replace("/[ #\&\+\-%@=\/\\\:;,\'\"\^`~|\!\?\*$#<>()\[\]\{\}]/", "", $_POST["filesrc"]) : '';
|
||||
|
||||
if( !$filesrc ){
|
||||
if( !$filesrc || ! preg_match('=^[^/?*;:{}\\\\]+\.[^/?*;:{}\\\\]+$=', $filesrc) || ! preg_match('/\.(gif|jpe?g|bmp|png)$/i', $filesrc) ){
|
||||
die( false );
|
||||
}
|
||||
|
||||
|
||||
@@ -1064,7 +1064,11 @@ DoUpload.prototype = {
|
||||
|
||||
if (evt.target.readyState === FileReader.DONE) {
|
||||
blob = new self.MyBlob(self.NewBlob(evt.target.result, filetype));
|
||||
orientation = self.getOrientation(evt.target.result.slice(0, 64 * 1024));
|
||||
try {
|
||||
orientation = self.getOrientation(evt.target.result.slice(0, 64 * 1024));
|
||||
} catch(err) {
|
||||
|
||||
}
|
||||
image = new Image();
|
||||
|
||||
image.onload = function () {
|
||||
|
||||
@@ -4,3 +4,9 @@ www.youtube(?:-nocookie)?.com/
|
||||
serviceapi.rmcnmv.naver.com/
|
||||
videofarm.daum.net/
|
||||
player.vimeo.com/
|
||||
maps.google.com/
|
||||
play.afreeca.com/
|
||||
v.nate.com/
|
||||
www.microsoft.com/showcase/video.aspx/
|
||||
w.soundcloud.com/
|
||||
www.facebook.com/
|
||||
@@ -245,7 +245,7 @@ function captcha_html($class="captcha")
|
||||
$html .= "\n".'<script src="'.G5_CAPTCHA_URL.'/kcaptcha.js"></script>';
|
||||
$html .= "\n".'<fieldset id="captcha" class="'.$class.'">';
|
||||
$html .= "\n".'<legend><label for="captcha_key">자동등록방지</label></legend>';
|
||||
if (is_mobile()) $html .= '<audio src="#" id="captcha_audio" controls></audio>';
|
||||
if (is_mobile()) $html .= '<audio id="captcha_audio" controls></audio>';
|
||||
//$html .= "\n".'<img src="#" alt="" id="captcha_img">';
|
||||
$html .= "\n".'<img src="javascript:void(0);" alt="" id="captcha_img">';
|
||||
if (!is_mobile()) $html .= "\n".'<button type="button" id="captcha_mp3"><span></span>숫자음성듣기</button>';
|
||||
|
||||
@@ -39,7 +39,7 @@ if (G5_IS_MOBILE) {
|
||||
echo '<meta name="format-detection" content="telephone=no">'.PHP_EOL;
|
||||
} else {
|
||||
echo '<meta http-equiv="imagetoolbar" content="no">'.PHP_EOL;
|
||||
echo '<meta http-equiv="X-UA-Compatible" content="IE=10,chrome=1">'.PHP_EOL;
|
||||
echo '<meta http-equiv="X-UA-Compatible" content="IE=Edge">'.PHP_EOL;
|
||||
}
|
||||
|
||||
if($config['cf_add_meta'])
|
||||
|
||||
Reference in New Issue
Block a user