diff --git a/main/exercice/Hpdownload.php b/main/exercice/Hpdownload.php index 2118567c43..cd04cca715 100644 --- a/main/exercice/Hpdownload.php +++ b/main/exercice/Hpdownload.php @@ -22,7 +22,7 @@ * This script shows the list of exercises for administrators and students. * @package dokeos.exercise * @author Istvan Mandak -* @version $Id: Hpdownload.php 20555 2009-05-12 14:01:40Z juliomontoya $ +* @version $Id: Hpdownload.php 21122 2009-05-31 00:10:22Z cfasanando $ */ @@ -35,7 +35,7 @@ include(api_get_path(LIBRARY_PATH)."events.lib.inc.php"); $tbl_document = Database::get_course_table(TABLE_DOCUMENT); -$doc_url=str_replace(array('../','\\..','\\0'),array('','',''),urldecode($_GET['doc_url'])); +$doc_url=str_replace(array('../','\\..','\\0','..\\'),array('','','',''),urldecode($_GET['doc_url'])); $filename=basename($doc_url); // launch event