xssClean uploaded file name

This commit is contained in:
Matt Pass
2016-08-31 14:34:00 +01:00
parent 94ca7bbe32
commit e9d7c7817f

View File

@@ -748,7 +748,7 @@ if (!isset($ftpSite) && !$error && $_GET['action']=="upload") {
function getDetails($fileArr) {
foreach($fileArr['name'] as $keyee => $info) {
$uploads[$keyee]->name=$fileArr['name'][$keyee];
$uploads[$keyee]->name=xssClean($fileArr['name'][$keyee],"html");
$uploads[$keyee]->type=$fileArr['type'][$keyee];
$uploads[$keyee]->tmp_name=$fileArr['tmp_name'][$keyee];
$uploads[$keyee]->error=$fileArr['error'][$keyee];