1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
|
<?php /************************* Coppermine Photo Gallery ************************ Copyright (c) 2003-2008 Dev Team v1.1 originally written by Gregory DEMAR
This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License version 3 as published by the Free Software Foundation. ******************************************** Coppermine version: 1.4.19 $HeadURL: https://coppermine.svn.sourceforge.net/svnroot/coppermine/trunk/cpg1.4.x/addpic.php $ $Revision: 4392 $ $Author: gaugau $ $Date: 2008-04-16 09:25:35 +0200 (Mi, 16 Apr 2008) $ **********************************************/
/** * Coppermine Photo Gallery addpic.php * * This file file gets called in the img src when you do batch add, there is nothing * much to look here the grunt work is done by the function add_picture * * @copyright 2002,2007 Gregory DEMAR, Coppermine Dev Team * @license http://www.gnu.org/licenses/gpl.html GNU General Public License V3 * @package Coppermine * @version $Id: addpic.php 4392 2008-04-16 07:25:35Z gaugau $ */
/** * @ignore */ define('IN_COPPERMINE', true);
define('ADDPIC_PHP', true);
require('include/init.inc.php'); require('include/picmgmt.inc.php');
if (!GALLERY_ADMIN_MODE) die('Access denied');
$aid = (int)$_GET['aid']; $pic_file = base64_decode($_GET['pic_file']); $dir_name = dirname($pic_file) . '/'; $file_name = basename($pic_file);
# Create the holder $picture_name by translating the file name. # Translate any forbidden character into an underscore. $sane_name = replace_forbidden($file_name); $source = './'.$CONFIG['fullpath'].$dir_name.$file_name; rename($source, './' . $CONFIG['fullpath'] . $dir_name . $sane_name); $sql = "SELECT pid FROM {$CONFIG['TABLE_PICTURES']} WHERE filepath='" . addslashes($dir_name) . "' AND filename='" . addslashes($file_name) . "' LIMIT 1"; $result = cpg_db_query($sql);
if (mysql_num_rows($result)) { $file_name = 'images/up_dup.gif'; } elseif (add_picture($aid, $dir_name, $sane_name)) { $file_name = 'images/up_ok.gif'; } else { $file_name = 'images/up_pb.gif'; echo $ERROR; }
if (ob_get_length()) { ob_end_flush(); exit; }
header('Content-type: image/gif'); echo fread(fopen($file_name, 'rb'), filesize($file_name)); ob_end_flush() ?>
|