Upload

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Upload

    ANYONE NOW HOW TO RESTRICT FILES LIKE PHP,HTML,ASP,ASPX ETC FROM BEING UPLOADED USING THIS IV TRIED A FEW METHODS BUT THEY HAVE BEEN ANY GOOD THANKS !




    Code:
    $Connect = mysql_connect("$server","$user","$pass");
    mysql_select_db("$dbname");
    $result=mysql_query("select * from members where username='$username' and password='$password'");
    $number_of_rows = mysql_num_rows($result);
    if ($number_of_rows>0)
    {
        include("../check.inc.php");
    }
    if ($ok>0)
    {
    
    
    if($action=="upload")
    {
    echo "[b]Upload![/b]
    ";
    echo "~=~=~=~=~
    ";
    
       echo "<form align=\"center\" action=\"up.php?action=updone&amp;username=$username&amp;password=$password&amp;cat=$cat\" method=\"post\" ENCTYPE=\"multipart/form-data\">";
       echo "File: <input type=\"file\" name=\"fpic\" size=\"30\"/>
    ";
       echo "<input type=\"submit\" value=\"Upload!\"/>";
       echo "</form>";
    echo "~=~=~=~=~
    ";
    echo "<a title=\"Enter\" href=\"cat.php?username=$username&amp;password=$password&amp;cat=$cat\">Back</a>";
    }
    else if($action=="updone")
    {
    
    echo "[b]Uploaded![/b]
    ";
    echo "~=~=~=~=~
    ";
    if($fpic=="")
    {
    echo "error";
    }
    else
    {
    
        $file = $_FILES["fpic"];
        if(is_uploaded_file($file["tmp_name"]))
        {
            move_uploaded_file($file["tmp_name"], "$cat/".$file["name"]);
        }
      
    $furl = "$cat/".$file["name"]."";
    
    $sql = "INSERT INTO gal (username,cat,link) VALUES
    (&#39;$username&#39;,&#39;$cat&#39;,&#39;$furl&#39;)";
    $result = mysql_query($sql);
    }
    echo "<a title=\"Enter\" href=\"cat.php?username=$username&amp;password=$password&amp;cat=$cat\">Back</a>";
    
    }
    
    }
    echo "</p>"; 
    echo "</card>"; 
    echo "</wml>"; 
    ?>
    Want something coded email me at sales@webnwaphost.com for a prices.





    #2
    Code:
    $Connect = mysql_connect("$server","$user","$pass");
    mysql_select_db("$dbname");
    $result=mysql_query("select * from members where username=&#39;$username&#39; and password=&#39;$password&#39;");
    $number_of_rows = mysql_num_rows($result);
    if ($number_of_rows>0)
    {
        include("../check.inc.php");
    }
    if ($ok>0)
    {
    
    
    if($action=="upload")
    {
    echo "[b]Upload![/b]
    ";
    echo "~=~=~=~=~
    ";
    
       echo "<form align=\"center\" action=\"up.php?action=updone&amp;username=$username&amp;password=$password&amp;cat=$cat\" method=\"post\" ENCTYPE=\"multipart/form-data\">";
       echo "File: <input type=\"file\" name=\"fpic\" size=\"30\"/>
    ";
       echo "<input type=\"submit\" value=\"Upload!\"/>";
       echo "</form>";
    echo "~=~=~=~=~
    ";
    echo "<a title=\"Enter\" href=\"cat.php?username=$username&amp;password=$password&amp;cat=$cat\">Back</a>";
    }
    else if($action=="updone")
    {
    
    echo "[b]Uploaded![/b]
    ";
    echo "~=~=~=~=~
    ";
    if($fpic=="")
    {
    echo "error";
    }
    else
    {
    
        $file = $_FILES["fpic"];
    $file = str_replace("php","+",$file);
    $file = str_replace("asp","+",$file);
    $file = str_replace("aspx","+",$file);
    $file = str_replace(" ","20%",$file);
        if(is_uploaded_file($file["tmp_name"]))
        {
            move_uploaded_file($file["tmp_name"], "$cat/".$file["name"]);
        }
    
      
    $furl = "$cat/".$file["name"]."";
    
    $sql = "INSERT INTO gal (username,cat,link) VALUES
    (&#39;$username&#39;,&#39;$cat&#39;,&#39;$furl&#39;)";
    $result = mysql_query($sql);
    }
    echo "<a title=\"Enter\" href=\"cat.php?username=$username&amp;password=$password&amp;cat=$cat\">Back</a>";
    
    }
    
    }
    echo "</p>"; 
    echo "</card>"; 
    echo "</wml>"; 
    ?>
    Visit: Chat4u.mobi - The New Lay Of being a site of your dreams!
    Visit: WapMasterz Coming Back Soon!
    _______
    SCRIPTS FOR SALE BY SUBZERO
    Chat4u Script : coding-talk.com/f28/chat4u-mobi-script-only-150-a-17677/ - > Best Script for your site no other can be hacked by sql or uploaders.
    FileShare Script : coding-talk.com/f28/file-wap-share-6596/ -> Uploader you will never regret buying yeah it mite be old now but it still seems to own others...
    _______
    Info & Tips
    php.net
    w3schools.com

    Comment


      #3
      cheers bro al try tht
      Want something coded email me at sales@webnwaphost.com for a prices.




      Comment

      Working...
      X