E anche il file upload.php
[php]<?php
include("../web/core.php");
include("../web/config.php");
connectdb();
$uip = getip();
$action = $_POST["action"];
$sid = $_POST["sid"];
$page = $_POST["page"];
$who = $_POST["who"];
$uid = getuid_sid($sid);
$sid = $POST["sid"];
$site = $POST["site"];
$theme = mysql_fetch_array(mysql_query("SELECT theme FROM ibwf_users WHERE id='".$uid."'"));
$sitename = mysql_fetch_array(mysql_query("SELECT value FROM ibwf_settings WHERE name='sitename'"));
$sitename = $sitename[0];
echo '<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html"/>
<meta http-equiv="Cache-Control" content="no-cache" forua="true"/>';
echo "<title>$sitename Upload Files</title>";
echo "<link rel="stylesheet" type="text/css" href="../themes/$theme[0]">";
echo "</head>";
echo "<body bgcolor="#FFFFFF" text="#000000" link="#0000FF" vlink="#800080">";
if ($upload="upload"&&$superdat_name){
if (!eregi(".(mid|gif|bmp|mid|midi|3gp|mp3|wav|jar|jad|jpeg|jpg|sis|mmf|amr|png|wbmp)$",$superdat_name)){
print "<b>Unsupported File Extention!</b>";
}else{
$superdat_name = preg_replace(
'/[^a-zA-Z0-9.$%'`-@{}~!#()&_^]/'
,'',str_replace(array(' ','%20',"'"),array('','', ""),$superdat_name));
if(strlen($superdat_name)>53){ print "<b>File Name Is Too Long!</b>";
}else{
if (empty($superdat)) {
print "<b>No input file specified!!!</b>";
}else{
copy("$superdat", "files/$superdat_name") or
die("Couldn't copy file.");
$date=(date("D, j F Y"));
$fsize=round($superdat_size/1024,1);
$text = "&&$superdat_name&&$fsize KB&&$date&&$REMOTE_ADDR&&";
$fz = "$fsize KB";
if("$text"!="$check[1]"){
$mysql=mysql_query("INSERT INTO ibwf_uploads SET id='', uid='".$uid."', filename='".$superdat_name."', filesize='".$fsize." KB', date='".$date."', uip='".$REMOTE_ADDR."'");
echo mysql_error();
}
echo "<b>$superdat_name</b> has successfully been uploaded to our uploader";
}
}
}
}
?>
<?php
echo "<FORM align="center" ACTION="upload.php?sid=$sid&site=$site" METHOD="POST" ENCTYPE="multipart/form-data">";
?>
<b>Select File To Be Uploaded :</b><br/>
<input align="center" type="file" name="superdat"><br/>
<input align="center" type="hidden" name="upload" value="upload"/>
<INPUT align="center" TYPE=SUBMIT NAME="submit" VALUE="Upload File!"><br/><br/></small><br/> <b><u>You can only upload files with folowing extentions:</u></b><br/>
.jpg, .jpeg, .gif, .png, .bmp, wbmp, .mid, .midi, .mpg, .mmf, .amr, .mp3, .wav, .wmv , .avi, .3gp, .sis, .jar, .jad, .zip, .rar, .txt<br/>
<?php echo "<br/><small><a href="index.php?sid=$sid&site=$site">Uploaded Files</a></small>"; ?>
</FORM>
<?php
if($site=="wap"){
echo "<br/><br/><a href="../wap/index.php?action=main&sid=$sid"><img src="../images/.gif" alt=""/>Home</a>";
}else{
echo "<br/><br/><a href="../web/index.php?action=main&sid=$sid"><img src="../images/.gif" alt=""/>Home</a>";
}
?>
</body>
</html>[/php]Come si può sistemare?:?