<?xml version="1.0" encoding="utf-8"?>
<feed xml:lang="en" xmlns="http://www.w3.org/2005/Atom"><title>Recent changes to bugs</title><link href="https://sourceforge.net/p/phpanti-leech/bugs/" rel="alternate"/><link href="https://sourceforge.net/p/phpanti-leech/bugs/feed.atom" rel="self"/><id>https://sourceforge.net/p/phpanti-leech/bugs/</id><updated>2009-04-12T09:52:37Z</updated><subtitle>Recent changes to bugs</subtitle><entry><title>Path check on presence ".."</title><link href="https://sourceforge.net/p/phpanti-leech/bugs/1/" rel="alternate"/><published>2009-04-12T09:52:37Z</published><updated>2009-04-12T09:52:37Z</updated><author><name>Anonymous</name><uri>https://sourceforge.net/u/userid-None/</uri></author><id>https://sourceforge.net3aa264478dd1820d53cf20ec2d4a5d2a22b3ce8d</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;File: download.php&lt;br /&gt;
It seems to me that instead of string:&lt;br /&gt;
if(strpos($fullfilename,"..")==true){&lt;/p&gt;
&lt;p&gt;Should be:&lt;br /&gt;
if(strpos($fullfilename,'..')!==false){&lt;/p&gt;
&lt;p&gt;For example: function strpos ('./path/file.zip ', '. ') will return 0 which it will be transformed to false&lt;/p&gt;&lt;/div&gt;</summary></entry></feed>