1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37
| <?php
require("fonctions.php");
if (isset($_GET["line"]))
{
// tu colles en session des donnée en provenance d'une url sans aucun contrôle !!
$_SESSION['id'] = $_GET["line"]; // $_SESSION['id'] = intval($_GET["line"]); je pense au minimum
if (isset($_GET["random"]))
{
$_SESSION['random'] = $_GET["random"];
}
}
else
{
$upload_path = $_SERVER['DOCUMENT_ROOT']."/glossaire/audio/";
$filename = $_SESSION['id'].$_SESSION['random'];
echo 'session[id] = ', $_SESSION['id'];
$requete = "SELECT * FROM glo_glossaire WHERE id_glo=".$_SESSION['id'];
$result = mysql_query($requete) or die (mysql_error());
$row = mysql_fetch_array($result);
if ( ! empty($row))
{
maj_mot($_SESSION['id'], $row['mot_glo'], $row['pho_glo'], $row['com_glo'], $filename, $row['fic_glo']);
}
else
{
exit('aucun enregistrement dans acceptfile.php');
}
$fp = fopen($upload_path.$filename.".wav", "wb");
fwrite($fp, file_get_contents('php://input'));
fclose($fp);
exit('done');
}
?> |
Partager