diff --git a/htdocs/adherents/document.php b/htdocs/adherents/document.php index bd68b50b44583..2a5786f14b247 100644 --- a/htdocs/adherents/document.php +++ b/htdocs/adherents/document.php @@ -75,7 +75,7 @@ if (dol_mkdir($upload_dir) >= 0) { - $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . $_FILES['userfile']['name'],0,0,$_FILES['userfile']['error']); + $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . stripslashes($_FILES['userfile']['name']),0,0,$_FILES['userfile']['error']); if (is_numeric($resupload) && $resupload > 0) { if (image_format_supported($upload_dir . "/" . $_FILES['userfile']['name']) == 1) diff --git a/htdocs/admin/security_other.php b/htdocs/admin/security_other.php index f14b719d41a2c..6596d91844c57 100644 --- a/htdocs/admin/security_other.php +++ b/htdocs/admin/security_other.php @@ -46,7 +46,7 @@ $result=dol_mkdir($upload_dir); // Create dir if not exists if ($result >= 0) { - $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . $_FILES['userfile']['name'],1,0,$_FILES['userfile']['error']); + $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . stripslashes($_FILES['userfile']['name']),1,0,$_FILES['userfile']['error']); if (is_numeric($resupload) && $resupload > 0) { diff --git a/htdocs/comm/action/document.php b/htdocs/comm/action/document.php index 448ba78d1587e..a948d91c0e76f 100755 --- a/htdocs/comm/action/document.php +++ b/htdocs/comm/action/document.php @@ -73,7 +73,7 @@ if (dol_mkdir($upload_dir) >= 0) { - $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . $_FILES['userfile']['name'],0,0,$_FILES['userfile']['error']); + $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . stripslashes($_FILES['userfile']['name']),0,0,$_FILES['userfile']['error']); if (is_numeric($resupload) && $resupload > 0) { if (image_format_supported($upload_dir . "/" . $_FILES['userfile']['name']) == 1) diff --git a/htdocs/comm/propal/document.php b/htdocs/comm/propal/document.php index a55a407b71be1..5e6b4f9a9b192 100644 --- a/htdocs/comm/propal/document.php +++ b/htdocs/comm/propal/document.php @@ -75,7 +75,7 @@ if (dol_mkdir($upload_dir) >= 0) { - $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . $_FILES['userfile']['name'],0,0,$_FILES['userfile']['error']); + $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . stripslashes($_FILES['userfile']['name']),0,0,$_FILES['userfile']['error']); if (is_numeric($resupload) && $resupload > 0) { if (image_format_supported($upload_dir . "/" . $_FILES['userfile']['name']) == 1) diff --git a/htdocs/commande/document.php b/htdocs/commande/document.php index f45e0b407d85e..3e890ea13f8fd 100644 --- a/htdocs/commande/document.php +++ b/htdocs/commande/document.php @@ -78,7 +78,7 @@ if (dol_mkdir($upload_dir) >= 0) { - $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . $_FILES['userfile']['name'],0,0,$_FILES['userfile']['error']); + $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . stripslashes($_FILES['userfile']['name']),0,0,$_FILES['userfile']['error']); if (is_numeric($resupload) && $resupload > 0) { if (image_format_supported($upload_dir . "/" . $_FILES['userfile']['name']) == 1) diff --git a/htdocs/compta/facture/document.php b/htdocs/compta/facture/document.php index d3048dcfd119f..7a3bc8b06a4c3 100644 --- a/htdocs/compta/facture/document.php +++ b/htdocs/compta/facture/document.php @@ -80,7 +80,7 @@ if (dol_mkdir($upload_dir) >= 0) { - $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . $_FILES['userfile']['name'],0,0,$_FILES['userfile']['error']); + $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . stripslashes($_FILES['userfile']['name']),0,0,$_FILES['userfile']['error']); if (is_numeric($resupload) && $resupload > 0) { if (image_format_supported($upload_dir . "/" . $_FILES['userfile']['name']) == 1) diff --git a/htdocs/compta/prelevement/fiche.php b/htdocs/compta/prelevement/fiche.php index 8441800d18f13..f7e73d64276c1 100644 --- a/htdocs/compta/prelevement/fiche.php +++ b/htdocs/compta/prelevement/fiche.php @@ -67,7 +67,7 @@ { $dir = $conf->prelevement->dir_output.'/receipts'; - if (dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $dir . "/" . $_FILES['userfile']['name'],1) > 0) + if (dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $dir . "/" . stripslashes($_FILES['userfile']['name']),1) > 0) { $dt = dol_mktime(12,0,0,GETPOST('remonth','int'),GETPOST('reday','int'),GETPOST('reyear','int')); diff --git a/htdocs/compta/sociales/document.php b/htdocs/compta/sociales/document.php index 82962f224ebcb..797945d8ee79e 100644 --- a/htdocs/compta/sociales/document.php +++ b/htdocs/compta/sociales/document.php @@ -75,7 +75,7 @@ { if (dol_mkdir($upload_dir) >= 0) { - $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . $_FILES['userfile']['name'],0,0,$_FILES['userfile']['error']); + $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . stripslashes($_FILES['userfile']['name']),0,0,$_FILES['userfile']['error']); if (is_numeric($resupload) && $resupload > 0) { if (image_format_supported($upload_dir . "/" . $_FILES['userfile']['name']) == 1) diff --git a/htdocs/contrat/document.php b/htdocs/contrat/document.php index ea04ce4e33f78..5180b8a1dd6b7 100644 --- a/htdocs/contrat/document.php +++ b/htdocs/contrat/document.php @@ -72,7 +72,7 @@ { if (dol_mkdir($upload_dir) >= 0) { - $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . $_FILES['userfile']['name'],0,0,$_FILES['userfile']['error']); + $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . stripslashes($_FILES['userfile']['name']),0,0,$_FILES['userfile']['error']); if (is_numeric($resupload) && $resupload > 0) { if (image_format_supported($upload_dir . "/" . $_FILES['userfile']['name']) == 1) diff --git a/htdocs/ecm/docmine.php b/htdocs/ecm/docmine.php index 55db3ddb2840b..8f253c04e4b79 100644 --- a/htdocs/ecm/docmine.php +++ b/htdocs/ecm/docmine.php @@ -75,7 +75,7 @@ { if (dol_mkdir($upload_dir) >= 0) { - $resupload = dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . $_FILES['userfile']['name'],0,0,$_FILES['userfile']['error']); + $resupload = dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . stripslashes($_FILES['userfile']['name']),0,0,$_FILES['userfile']['error']); if (is_numeric($resupload) && $resupload > 0) { $result=$ecmdir->changeNbOfFiles('+'); diff --git a/htdocs/ecm/docother.php b/htdocs/ecm/docother.php index c07a4d799a71c..cfc9e6aee74e5 100644 --- a/htdocs/ecm/docother.php +++ b/htdocs/ecm/docother.php @@ -45,7 +45,7 @@ { if (dol_mkdir($upload_dir) >= 0) { - $resupload = dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . $_FILES['userfile']['name'],0,0,$_FILES['userfile']['error']); + $resupload = dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . stripslashes($_FILES['userfile']['name']),0,0,$_FILES['userfile']['error']); if (is_numeric($resupload) && $resupload > 0) { $result=$ecmdir->changeNbOfFiles('+'); diff --git a/htdocs/ecm/index.php b/htdocs/ecm/index.php index 9eac55e9fc9b0..5c0b178c6ede8 100644 --- a/htdocs/ecm/index.php +++ b/htdocs/ecm/index.php @@ -94,7 +94,7 @@ if (dol_mkdir($upload_dir) >= 0) { - $resupload = dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . $_FILES['userfile']['name'],0, 0, $_FILES['userfile']['error']); + $resupload = dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . stripslashes($_FILES['userfile']['name']),0, 0, $_FILES['userfile']['error']); if (is_numeric($resupload) && $resupload > 0) { //$mesg = '
'.$langs->trans("FileTransferComplete").'
'; diff --git a/htdocs/fichinter/document.php b/htdocs/fichinter/document.php index fa191941303b8..a4dbe96b51692 100644 --- a/htdocs/fichinter/document.php +++ b/htdocs/fichinter/document.php @@ -76,7 +76,7 @@ if (dol_mkdir($upload_dir) >= 0) { - $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . $_FILES['userfile']['name'],0,0,$_FILES['userfile']['error']); + $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . stripslashes($_FILES['userfile']['name']),0,0,$_FILES['userfile']['error']); if (is_numeric($resupload) && $resupload > 0) { if (image_format_supported($upload_dir . "/" . $_FILES['userfile']['name']) == 1) diff --git a/htdocs/fourn/commande/document.php b/htdocs/fourn/commande/document.php index 4a04ef2a5647e..fb5d9df5d2336 100644 --- a/htdocs/fourn/commande/document.php +++ b/htdocs/fourn/commande/document.php @@ -79,7 +79,7 @@ if (dol_mkdir($upload_dir) >= 0) { - $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . $_FILES['userfile']['name'],0,0,$_FILES['userfile']['error']); + $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . stripslashes($_FILES['userfile']['name']),0,0,$_FILES['userfile']['error']); if (is_numeric($resupload) && $resupload > 0) { if (image_format_supported($upload_dir . "/" . $_FILES['userfile']['name']) == 1) diff --git a/htdocs/fourn/facture/document.php b/htdocs/fourn/facture/document.php index 5a0e20cf31bb4..51fdf70f4a52b 100644 --- a/htdocs/fourn/facture/document.php +++ b/htdocs/fourn/facture/document.php @@ -75,7 +75,7 @@ if (dol_mkdir($upload_dir) >= 0) { - $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . $_FILES['userfile']['name'],0,0,$_FILES['userfile']['error']); + $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . stripslashes($_FILES['userfile']['name']),0,0,$_FILES['userfile']['error']); if (is_numeric($resupload) && $resupload > 0) { if (image_format_supported($upload_dir . "/" . $_FILES['userfile']['name']) == 1) diff --git a/htdocs/ftp/index.php b/htdocs/ftp/index.php index 9849671f5d099..9b286641f3272 100644 --- a/htdocs/ftp/index.php +++ b/htdocs/ftp/index.php @@ -95,7 +95,7 @@ if (dol_mkdir($upload_dir) >= 0) { - $resupload = dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . $_FILES['userfile']['name'],0); + $resupload = dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . stripslashes($_FILES['userfile']['name']),0); if (is_numeric($resupload) && $resupload > 0) { //$mesg = '
'.$langs->trans("FileTransferComplete").'
'; diff --git a/htdocs/product/document.php b/htdocs/product/document.php index cf5835e1c3a9d..791fa9e90be1c 100755 --- a/htdocs/product/document.php +++ b/htdocs/product/document.php @@ -76,7 +76,7 @@ { if (dol_mkdir($upload_dir) >= 0) { - $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . $_FILES['userfile']['name'],0,0,$_FILES['userfile']['error']); + $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . stripslashes($_FILES['userfile']['name']),0,0,$_FILES['userfile']['error']); if (is_numeric($resupload) && $resupload > 0) { if (image_format_supported($upload_dir . "/" . $_FILES['userfile']['name']) == 1) diff --git a/htdocs/projet/document.php b/htdocs/projet/document.php index 776023505403d..dd9a4fe2c6e06 100644 --- a/htdocs/projet/document.php +++ b/htdocs/projet/document.php @@ -75,7 +75,7 @@ if (dol_mkdir($upload_dir) >= 0) { - $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . $_FILES['userfile']['name'],0,0,$_FILES['userfile']['error']); + $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . stripslashes($_FILES['userfile']['name']),0,0,$_FILES['userfile']['error']); if (is_numeric($resupload) && $resupload > 0) { if (image_format_supported($upload_dir . "/" . $_FILES['userfile']['name']) == 1) diff --git a/htdocs/projet/tasks/document.php b/htdocs/projet/tasks/document.php index f77706f4c7f86..8095d83c9d6f9 100644 --- a/htdocs/projet/tasks/document.php +++ b/htdocs/projet/tasks/document.php @@ -73,7 +73,7 @@ { if (dol_mkdir($upload_dir) >= 0) { - $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . $_FILES['userfile']['name'],0,0,$_FILES['userfile']['error']); + $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . stripslashes($_FILES['userfile']['name']),0,0,$_FILES['userfile']['error']); if (is_numeric($resupload) && $resupload > 0) { if (image_format_supported($upload_dir . "/" . $_FILES['userfile']['name']) == 1) diff --git a/htdocs/societe/document.php b/htdocs/societe/document.php index a5e55ed4fe934..6ab8e8b5ee0ad 100644 --- a/htdocs/societe/document.php +++ b/htdocs/societe/document.php @@ -83,7 +83,7 @@ { if (dol_mkdir($upload_dir) >= 0) { - $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . $_FILES['userfile']['name'],0,0,$_FILES['userfile']['error']); + $resupload=dol_move_uploaded_file($_FILES['userfile']['tmp_name'], $upload_dir . "/" . stripslashes($_FILES['userfile']['name']),0,0,$_FILES['userfile']['error']); if (is_numeric($resupload) && $resupload > 0) { if (image_format_supported($upload_dir . "/" . $_FILES['userfile']['name']) == 1)