forked from Real-Gecko/Filemin
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathupload.cgi
105 lines (95 loc) · 3.3 KB
/
upload.cgi
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
#!/usr/bin/perl
require './filemin-lib.pl';
use Cwd 'abs_path';
&ReadParse(\%in, "GET");
get_paths();
my @errors;
$line = "";
# Use Webmin's callback function to track progress
$cbfunc = \&read_parse_mime_callback;
# Get multipart form boundary
$ENV{'CONTENT_TYPE'} =~ /boundary=(.*)$/ || &error($text{'readparse_enc'});
$boundary = $1;
# Comment right now
#if ($ENV{'CONTENT_LENGTH'} && $max && $ENV{'CONTENT_LENGTH'} > $max) {
# &error($err);
#}
# Initialize progress tracker
&$cbfunc(0, $ENV{'CONTENT_LENGTH'}, undef, $in{'id'});
#Read the data
while(index($line,"$boundary--") == -1) {
#reset vars on each loop
$file = undef;
$rest = undef;
$prevline = undef;
$header = undef;
$line = <STDIN>;
$got += length($line);
&$cbfunc($got, $ENV{'CONTENT_LENGTH'}, undef, $in{'id'});
if ($line =~ /(\S+):\s*form-data(.*)$/) {
$rest = $2; # We found form data definition, let`s check it
} else {
next;
}
# Check if current form data part is file
while ($rest =~ /([a-zA-Z]*)=\"([^\"]*)\"(.*)/) {
if ($1 eq 'filename') {
$file = $2;
}
$rest = $3;
}
if(defined($file)){
# OK, we have a file, let`s save it
if (-e "$cwd/$file") {
push @errors, "$path/$file $text{'error_exists'}";
next;
} else {
if (!open(OUTFILE, ">$cwd/$file")) {
push @errors, "$text{'error_opening_file_for_writing'} $path/$file - $!"; #die "Can't open $cwd/$file for writing - $!";
next;
} else {
binmode(OUTFILE);
# Skip "content-type" as we work in binmode anyway and skip empty line
<STDIN>; <STDIN>;
# Read all lines until next boundary or form data end
while(1) {
$line = <STDIN>;
# Inform progress tracker about our actions
$got += length($line);
&$cbfunc($got, $ENV{'CONTENT_LENGTH'}, $file, $in{'id'});
# Some brainf###ing to deal with last CRLF
if(index($line,"$boundary") != -1 || index($line,"$boundary--") != -1) {
chop($prevline);
chop($prevline);
if (!print OUTFILE $prevline) {
push errors, "text{'error_writing_file'} $path/$file";
last;
}
last;
} else {
if (!print OUTFILE $prevline) {
push errors, "text{'error_writing_file'} $path/$file";
last;
}
$prevline = $line;
}
}
# File saved, let`s go further
close(OUTFILE);
}
}
} else {
# Just skip everything until next boundary or form data end
while(index($line,"$boundary") == -1 or index($line,"$boundary--") == -1) {
$line = <STDIN>;
}
}
}
# Everything finished, inform progress tracker
&$cbfunc(-1, $ENV{'CONTENT_LENGTH'}, undef, $in{'id'});
#&ui_print_footer("index.cgi?path=$path", $text{'previous_page'});
if (scalar(@errors) > 0) {
print_errors(@errors);
} else {
&redirect("index.cgi?path=$path");
}