Reversed parameters on strpos, the needle should be './', it returns a numeric value and it should be substr_count anyway. Fixes CVE-2014-1137 (part 2) when user is logged in. Tested to not break functionality of project or single file downloads.