X-Git-Url: https://delta.frontaccounting.com/gitweb/?a=blobdiff_plain;f=admin%2Fbackups.php;h=24ec77b68a33d268368acdf744af544c41869340;hb=1d8bbcbf6bf6c663d83283be329758a936f863fa;hp=4011a2a5423eafddedb376cd8eab233d14ecd99e;hpb=d9b4de9d7e9d3ba77f6ece752fd6cc988effd8f1;p=fa-stable.git diff --git a/admin/backups.php b/admin/backups.php index 4011a2a5..24ec77b6 100644 --- a/admin/backups.php +++ b/admin/backups.php @@ -20,20 +20,20 @@ if (get_post('view')) { if (!get_post('backups')) { display_error(_('Select backup file first.')); } else { - $filename = BACKUP_PATH . get_post('backups'); + $filename = BACKUP_PATH . clean_file_name(get_post('backups')); if (in_ajax()) $Ajax->popup( $filename ); else { - header('Content-type: application/octet-stream'); + header('Content-type: text/plain'); header('Content-Length: '.filesize($filename)); - header("Content-Disposition: inline; filename=$filename"); + header("Content-Disposition: inline"); readfile($filename); exit(); } } }; if (get_post('download')) { - download_file(BACKUP_PATH . get_post('backups')); + download_file(BACKUP_PATH . clean_file_name(get_post('backups'))); exit; } @@ -122,6 +122,8 @@ function download_file($filename) $db_name = $_SESSION["wa_current_user"]->company; $conn = $db_connections[$db_name]; +$backup_name = clean_file_name(get_post('backups')); +$backup_path = BACKUP_PATH . $backup_name; if (get_post('creat')) { generate_backup($conn, get_post('comp'), get_post('comments')); @@ -129,24 +131,24 @@ if (get_post('creat')) { }; if (get_post('restore')) { - if (db_import(BACKUP_PATH . get_post('backups'), $conn)) + if (db_import($backup_path, $conn)) display_notification(_("Restore backup completed.")); } if (get_post('deldump')) { - if (unlink(BACKUP_PATH . get_post('backups'))) { + if (unlink($backup_path)) { display_notification(_("File successfully deleted.")." " - . _("Filename") . ": " . get_post('backups')); + . _("Filename") . ": " . $backup_name); $Ajax->activate('backups'); } else display_error(_("Can't delete backup file.")); -}; +} if (get_post('upload')) { $tmpname = $_FILES['uploadfile']['tmp_name']; - $fname = $_FILES['uploadfile']['name']; + $fname = clean_file_name($FILES['uploadfile']['name']); if (!preg_match("/.sql(.zip|.gz)?$/", $fname)) display_error(_("You can only upload *.sql backup files")); @@ -173,7 +175,7 @@ table_section_title(_("Backup scripts maintenance")); echo "".get_backup_file_combo().""; echo ""; start_table(); - submit_row('view',_("View Backup"), false, '', '', true); + submit_row('view',_("View Backup"), false, '', '', false); submit_row('download',_("Download Backup"), false, '', '', false); submit_row('restore',_("Restore Backup"), false, '','', 'process'); submit_js_confirm('restore',_("You are about to restore database from backup file.\nDo you want to continue?"));