Changeset 10338

Show
Ignore:
Timestamp:
10/04/10 14:04:54 (3 years ago)
Author:
p_lindheimer
Message:

fixes #4568 better validation

Files:

Legend:

Unmodified
Added
Removed
Modified
Copied
Moved
  • modules/branches/2.8/recordings/page.recordings.php

    r10299 r10338  
    205205      $dest = "{$usersnum}-"; 
    206206    } 
    207     $suffix = substr(strrchr($_FILES['ivrfile']['name'], "."), 1); 
     207    $suffix = preg_replace('/[^0-9a-zA-Z]/','',substr(strrchr($_FILES['ivrfile']['name'], "."), 1)); 
    208208    $destfilename = $recordings_save_path.$dest."ivrrecording.".$suffix; 
    209209    move_uploaded_file($_FILES['ivrfile']['tmp_name'], $destfilename);