ANYONE NOW HOW TO RESTRICT FILES LIKE PHP,HTML,ASP,ASPX ETC FROM BEING UPLOADED USING THIS IV TRIED A FEW METHODS BUT THEY HAVE BEEN ANY GOOD THANKS !
Code:
$Connect = mysql_connect("$server","$user","$pass");
mysql_select_db("$dbname");
$result=mysql_query("select * from members where username='$username' and password='$password'");
$number_of_rows = mysql_num_rows($result);
if ($number_of_rows>0)
{
include("../check.inc.php");
}
if ($ok>0)
{
if($action=="upload")
{
echo "[b]Upload![/b]
";
echo "~=~=~=~=~
";
echo "<form align=\"center\" action=\"up.php?action=updone&username=$username&password=$password&cat=$cat\" method=\"post\" ENCTYPE=\"multipart/form-data\">";
echo "File: <input type=\"file\" name=\"fpic\" size=\"30\"/>
";
echo "<input type=\"submit\" value=\"Upload!\"/>";
echo "</form>";
echo "~=~=~=~=~
";
echo "<a title=\"Enter\" href=\"cat.php?username=$username&password=$password&cat=$cat\">Back</a>";
}
else if($action=="updone")
{
echo "[b]Uploaded![/b]
";
echo "~=~=~=~=~
";
if($fpic=="")
{
echo "error";
}
else
{
$file = $_FILES["fpic"];
if(is_uploaded_file($file["tmp_name"]))
{
move_uploaded_file($file["tmp_name"], "$cat/".$file["name"]);
}
$furl = "$cat/".$file["name"]."";
$sql = "INSERT INTO gal (username,cat,link) VALUES
('$username','$cat','$furl')";
$result = mysql_query($sql);
}
echo "<a title=\"Enter\" href=\"cat.php?username=$username&password=$password&cat=$cat\">Back</a>";
}
}
echo "</p>";
echo "</card>";
echo "</wml>";
?>
Comment