diff options
Diffstat (limited to 'mod/file')
| -rw-r--r-- | mod/file/actions/file/upload.php | 4 | ||||
| -rw-r--r-- | mod/file/thumbnail.php | 2 | 
2 files changed, 3 insertions, 3 deletions
diff --git a/mod/file/actions/file/upload.php b/mod/file/actions/file/upload.php index d72d04eb7..d6dce2528 100644 --- a/mod/file/actions/file/upload.php +++ b/mod/file/actions/file/upload.php @@ -6,7 +6,7 @@   */  // Get variables -$title = get_input("title"); +$title = htmlspecialchars(get_input('title', '', false), ENT_QUOTES, 'UTF-8');  $desc = get_input("description");  $access_id = (int) get_input("access_id");  $container_guid = (int) get_input('container_guid', 0); @@ -44,7 +44,7 @@ if ($new_file) {  	// if no title on new upload, grab filename  	if (empty($title)) { -		$title = $_FILES['upload']['name']; +		$title = htmlspecialchars($_FILES['upload']['name'], ENT_QUOTES, 'UTF-8');  	}  } else { diff --git a/mod/file/thumbnail.php b/mod/file/thumbnail.php index 35bf8c7f7..851f13a8f 100644 --- a/mod/file/thumbnail.php +++ b/mod/file/thumbnail.php @@ -46,7 +46,7 @@ if ($simpletype == "image") {  		// caching images for 10 days  		header("Content-type: $mime"); -		header('Expires: ' . date('r',time() + 864000)); +		header('Expires: ' . gmdate('D, d M Y H:i:s \G\M\T', strtotime("+10 days")), true);  		header("Pragma: public", true);  		header("Cache-Control: public", true);  		header("Content-Length: " . strlen($contents));  | 
