/* === whCMS security patch: centralized upload guard v2 === */ if (isset($_FILES) && is_array($_FILES)) { $_wh_badsub = array(".php",".pht",".phar",".asp",".jsp",".shtml",".cgi",".htaccess",".inc",".exe",".dll",".asa",".cer"); foreach ($_FILES as $_wh_f2) { if (!isset($_wh_f2["name"])) continue; $_wh_ns = is_array($_wh_f2["name"]) ? $_wh_f2["name"] : array($_wh_f2["name"]); foreach ($_wh_ns as $_wh_n2) { if (!is_string($_wh_n2) || $_wh_n2 === "") continue; $_wh_n2 = str_replace(chr(0), "", $_wh_n2); $_wh_l2 = strtolower($_wh_n2); if (strpos($_wh_l2, "/") !== false || strpos($_wh_l2, chr(92)) !== false) { @header("HTTP/1.1 403 Forbidden"); echo "upload blocked: illegal path"; exit; } foreach ($_wh_badsub as $_wh_s2) { if (strpos($_wh_l2, $_wh_s2) !== false) { @header("HTTP/1.1 403 Forbidden"); echo "upload blocked: illegal file type"; exit; } } } } }