#include "msgbase.h"
#include "citserver.h"
#include "threads.h"
-
-#ifndef HAVE_SNPRINTF
-#include "snprintf.h"
-#endif
-
#include "ctdl_module.h"
#include "user_ops.h"
ERROR + FILE_NOT_FOUND);
return;
}
+ if (strstr(filename, "../") != NULL)
+ {
+ cprintf("%d syntax error.\n",
+ ERROR + ILLEGAL_VALUE);
+ return;
+ }
if (CC->download_fp != NULL) {
cprintf("%d You already have a download file open.\n",
filename[a] = '_';
}
}
+ if (strstr(filename, "../") != NULL)
+ {
+ cprintf("%d syntax error.\n",
+ ERROR + ILLEGAL_VALUE);
+ return;
+ }
+
snprintf(pathname, sizeof pathname,
"%s/%s",
ctdl_image_dir,