diff --git a/img/imgup.php b/img/imgup.php
deleted file mode 100755
index c5f973c..0000000
--- a/img/imgup.php
+++ /dev/null
@@ -1,142 +0,0 @@
-
-
-
-
-
-
-
- ';
-
- if(!isset($_POST['submit'])) die("You didn't upload anything"); // check if submit has been posted if not then we know no upload is coming
- if(!isset($_POST['comment'])){ // check to see if there was a comment, if not print no comment
- $comment = "No Comment";
- }else{
- $comment = $_POST['comment'];
- }
- if(!isset($_SESSION['myusername'])){ // used later when login system is implemented allow anonymous uploads
- $username = 'Anonymous Coward'; // a little joke that stems from /.
- }else{
- $username = $_SESSION['myusername']; // username is username
- }
-
- $name = $_FILES["file"]["name"]; // shorten these array parts to variables
- $type = $_FILES["file"]["type"];
- $size = ($_FILES["file"]["size"] / 1024); // get size of file in Kb
- $time = date("d/j/y - g:i:s a"); // current date - time
-
- $name = cln_file_name($name);
- $type = sanatize($type); // people can spoof their mime types to have bad stuff in them - it's a stretch but better safe than sorry
- $size = sanatize($size); // just in case the size is not mysql safe clean it anyways
- $comment = sanatize($comment); // clean comment as it's user entered data
-
- $size = round($size, 2)." Kb"; // shorten size to #.## instead of longer
-
- $file_ext = pathinfo($_FILES['file']['name'], PATHINFO_EXTENSION);
- if(!in_array($file_ext, $extensions))die("Wrong or no file extension"); // stop the upload if it's wrong
- $name = rand().".".$file_ext;
-
- if (($_FILES["file"]["size"] < 400000000)){
- if ($_FILES["file"]["error"] > 0){
- echo "Return Code: " . $_FILES["file"]["error"] . "
";
- }else{
- if (file_exists("Pictures/" . $name)){
- echo $name." already exists. ";
- }else{
- if(preg_match('/php/i', $name) || preg_match('/phtml/i', $name) || preg_match('/htaccess/i', $name)){
- echo $name." is not allowed, sorry about that...";
- }else{
- $sql="INSERT INTO $tbl_name (name, location, type, size, time, comment, username) VALUES ('$name', '$location', '$type', '$size', '$time', '$comment', '$username')";
- $result=mysql_query($sql);
- if($result){
- move_uploaded_file($_FILES["file"]["tmp_name"], "Pictures/" . $name);
- echo "Stored at:
". $name."";
- }else {
- echo "There was a problem trying to upload your file - Could be a database error";
- }
- }
- }
- }
- }else{
- die("File too big!");
- }
- echo '
-
-
-
- ';
-?>