1:   2:   3:   4:   5:   6:   7:   8:   9:  10:  11:  12:  13:  14:  15:  16:  17:  18:  19:  20:  21:  22:  23:  24:  25:  26:  27:  28:  29:  30:  31:  32:  33:  34:  35:  36:  37:  38:  39:  40:  41:  42:  43:  44:  45:  46:  47:  48:  49:  50:  51:  52:  53:  54:  55:  56:  57:  58:  59:  60:  61:  62:  63:  64:  65:  66:  67:  68:  69:  70:  71:  72:  73:  74:  75:  76:  77:  78:  79:  80:  81:  82:  83:  84:  85:  86:  87:  88:  89:  90:  91:  92:  93:  94:  95:  96:  97:  98:  99: 100: 101: 102: 103: 104: 105: 106: 107: 108: 109: 110: 111: 112: 113: 114: 115: 116: 117: 118: 119: 120: 121: 122: 123: 124: 125: 126: 127: 128: 129: 130: 131: 132: 133: 134: 135: 136: 137: 138: 139: 140: 141: 142: 143: 144: 145: 146: 147: 148: 149: 150: 151: 152: 153: 154: 155: 156: 157: 158: 159: 160: 161: 162: 163: 164: 165: 166: 167: 168: 169: 170: 171: 172: 173: 174: 175: 176: 177: 178: 179: 180: 181: 182: 183: 184: 185: 186: 187: 188: 189: 190: 191: 192: 193: 194: 195: 196: 197: 198: 199: 200: 201: 202: 203: 204: 205: 206: 207: 208: 209: 210: 211: 212: 213: 214: 215: 216: 217: 218: 219: 220: 221: 222: 223: 224: 225: 226: 227: 228: 229: 230: 231: 232: 233: 234: 235: 236: 237: 238: 239: 240: 241: 242: 243: 244: 245: 246: 247: 248: 249: 250: 251: 252: 253: 254: 255: 256: 257: 258: 259: 260: 261: 262: 263: 264: 265: 266: 267: 268: 269: 270: 271: 272: 273: 274: 275: 276: 277: 278: 279: 280: 281: 282: 283: 284: 285: 286: 287: 288: 289: 290: 291: 292: 293: 294: 295: 296: 297: 298: 299: 300: 301: 302: 303: 304: 305: 306: 307: 308: 309: 310: 311: 312: 313: 314: 315: 316: 317: 318: 319: 320: 321: 322: 323: 324: 325: 326: 327: 328: 329: 330: 331: 332: 333: 334: 335: 336: 337: 338: 339: 340: 341: 342: 343: 344: 345: 346: 347: 348: 349: 350: 351: 352: 353: 354: 355: 356: 357: 358: 359: 360: 361: 362: 363: 364: 365: 366: 367: 368: 369: 370: 371: 372: 373: 374: 375: 376: 377: 378: 379: 380: 381: 382: 383: 384: 385: 386: 387: 388: 389: 390: 391: 392: 393: 394: 395: 396: 397: 398: 399: 400: 401: 402: 403: 404: 405: 406: 407: 408: 409: 410: 411: 412: 413: 414: 415: 416: 417: 418: 419: 420: 421: 422: 423: 424: 425: 426: 427: 428: 429: 430: 431: 432: 433: 434: 435: 436: 437: 438: 439: 440: 441: 442: 443: 444: 445: 446: 447: 448: 449: 450: 451: 452: 453: 454: 455: 456: 457: 458: 459: 460: 461: 462: 463: 464: 465: 466: 467: 468: 469: 470: 471: 472: 473: 474: 475: 476: 477: 478: 479: 480: 481: 482: 483: 484: 485: 486: 487: 488: 489: 490: 491: 492: 493: 494: 495: 496: 497: 498: 499: 500: 501: 502: 503: 504: 505: 506: 507: 508: 509: 510: 511: 512: 513: 514: 515: 516: 517: 518: 519: 520: 521: 522: 523: 524: 525: 526: 527: 528: 529: 530: 531: 532: 533: 534: 535: 536: 537: 538: 539: 540: 541: 542: 543: 544: 545: 546: 547: 548: 549: 550: 551: 552: 553: 554: 555: 556: 557: 558: 559: 560: 561: 562: 563: 564: 565: 566: 567: 568: 569: 570: 571: 572: 573: 574: 575: 
<?php
function zpErrorHandler($errno, $errstr = '', $errfile = '', $errline = '') {
    
    if (func_num_args() == 5) {
        
        list($errno, $errstr, $errfile, $errline) = func_get_args();
    } else {
        
        $exc = func_get_arg(0);
        $errno = $exc->getCode();
        $errstr = $exc->getMessage();
        $errfile = $exc->getFile();
        $errline = $exc->getLine();
    }
    
    if (error_reporting() == 0 && !in_array($errno, array(E_USER_ERROR, E_USER_WARNING, E_USER_NOTICE))) {
        return;
    }
    $errorType = array(E_ERROR               => gettext('ERROR'),
                    E_WARNING            => gettext('WARNING'),
                    E_NOTICE             => gettext('NOTICE'),
                    E_USER_ERROR     => gettext('USER ERROR'),
                    E_USER_WARNING => gettext('USER WARNING'),
                    E_USER_NOTICE    => gettext('USER NOTICE'),
                    E_STRICT             => gettext('STRICT NOTICE')
    );
    
    if (array_key_exists($errno, $errorType)) {
        $err = $errorType[$errno];
    } else {
        $err = gettext("EXCEPTION ($errno)");
        $errno = E_ERROR;
    }
    $msg = sprintf(gettext('%1$s: %2$s in %3$s on line %4$s'), $err, $errstr, $errfile, $errline);
    debugLogBacktrace($msg, 1);
    return false;
}
function filesystemToInternal($filename) {
    global $_zp_UTF8;
    return str_replace('\\', '/', $_zp_UTF8->convert($filename, FILESYSTEM_CHARSET, LOCAL_CHARSET));
}
function internalToFilesystem($filename) {
    global $_zp_UTF8;
    return $_zp_UTF8->convert($filename, LOCAL_CHARSET, FILESYSTEM_CHARSET);
}
function sanitize_path($filename) {
    $filename = strip_tags(str_replace('\\', '/', $filename));
    $filename = preg_replace(array('/x00/', '/\/\/+/', '/\/\.\./', '/\/\./', '/:/', '/</', '/>/', '/\?/', '/\*/', '/\"/', '/\|/', '/\/+$/', '/^\/+/'), '', $filename);
    return $filename;
}
function sanitize_numeric($num) {
    if (is_numeric($num)) {
        return round($num);
    } else {
        return false;
    }
}
function sanitize_script($text) {
    return preg_replace('!<script.*>.*</script>!ixs', '', $text);
}
function sanitize($input_string, $sanitize_level = 3) {
    if (is_array($input_string)) {
        $output_string = array();
        foreach ($input_string as $output_key => $output_value) {
            $output_string[$output_key] = sanitize($output_value, $sanitize_level);
        }
    } else {
        $output_string = sanitize_string($input_string, $sanitize_level);
    }
    return $output_string;
}
function ksesProcess($input_string, $allowed_tags) {
    if (function_exists('kses')) {
        return kses($input_string, $allowed_tags);
    } else {
        return getBare($input_string);
    }
}
function getBare($content) {
  $content = preg_replace('~<script.*?/script>~is', '', $content);
  $content = preg_replace('~<style.*?/style>~is', '', $content);
  $content = preg_replace('~<!--.*?-->~is', '', $content);
  $content = strip_tags($content);
  $content = str_replace(' ', ' ', $content);
  return $content;
}
function sanitize_string($input, $sanitize_level) {
    if (is_string($input)) {
        $input = str_replace(chr(0), " ", $input);
        switch ($sanitize_level) {
            case 0:
                return $input;
            case 2:
                
                $input = sanitize_script($input);
                return ksesProcess($input, getAllowedTags('style_tags'));
            case 3:
                
                return getBare($input);
 
            case 1:
                
                $input = sanitize_script($input);
                return ksesProcess($input, getAllowedTags('allowed_tags'));
            case 4:
            default:
                
                return sanitize_script($input);
        }
    }
    return $input;
}
function prefix($tablename = NULL) {
    if(defined('DATABASE_PREFIX')) {
        $prefix = DATABASE_PREFIX;
    } else{
        $prefix = 'zp_'; 
    }
    return '`' . $prefix . $tablename . '`';
}
function getWhereClause($unique_set) {
    if (empty($unique_set))
        return ' ';
    $where = ' WHERE';
    foreach ($unique_set as $var => $value) {
        $where .= ' `' . $var . '` = ' . db_quote($value) . ' AND';
    }
    return substr($where, 0, -4);
}
function getSetClause($new_unique_set) {
    $i = 0;
    $set = ' SET';
    foreach ($new_unique_set as $var => $value) {
        $set .= ' `' . $var . '`=';
        if (is_null($value)) {
            $set .= 'NULL';
        } else {
            $set .= db_quote($value) . ',';
        }
    }
    return substr($set, 0, -1);
}
function db_name() {
    global $_zp_conf_vars;
    return $_zp_conf_vars['mysql_database'];
}
function db_count($table, $clause = NULL, $field = "*") {
    $sql = 'SELECT COUNT(' . $field . ') FROM ' . prefix($table) . ' ' . $clause;
    $result = query_single_row($sql);
    if ($result) {
        return array_shift($result);
    } else {
        return 0;
    }
}
function zp_error($message, $fatal = E_USER_ERROR) {
    
    printf(html_encode($message));
    trigger_error($message, $fatal);
}
function html_decode($string) {
    return html_entity_decode($string, ENT_QUOTES, 'UTF-8');
}
function html_encode($str) {
    return htmlspecialchars($str, ENT_FLAGS, LOCAL_CHARSET);
}
function html_encodeTagged($original, $allowScript = true) {
    $tags = array();
    $str = $original;
    
    if ($allowScript) {
        preg_match_all('!<script.*>.*</script>!ixs', $str, $matches);
        foreach (array_unique($matches[0]) as $key => $tag) {
            $tags[2]['%' . $key . '$j'] = $tag;
            $str = str_replace($tag, '%' . $key . '$j', $str);
        }
    } else {
        $str = preg_replace('|<a(.*)href(.*)=(.*)javascript|ixs', '%$x', $str);
        $tags[2]['%$x'] = '<a href=<strike>javascript</strike>';
        $str = preg_replace('|<(.*)onclick|ixs', '%$c', $str);
        $tags[2]['%$c'] = '<<strike>onclick</strike>';
    }
    
    $str = preg_replace('~<!--.*?-->~is', '', $str);
    
    preg_match_all("/<\/?\w+((\s+(\w|\w[\w-]*\w)(\s*=\s*(?:\".*?\"|'.*?'|[^'\">\s]+))?)+\s*|\s*)\/?>/i", $str, $matches);
    foreach (array_unique($matches[0]) as $key => $tag) {
        $tags[2]['%' . $key . '$s'] = $tag;
        $str = str_replace($tag, '%' . $key . '$s', $str);
    }
    $str = htmLawed($str);
    
    preg_match_all('/(&[a-z0-9#]+;)/i', $str, $matches);
    foreach (array_unique($matches[0]) as $key => $entity) {
        $tags[3]['%' . $key . '$e'] = $entity;
        $str = str_replace($entity, '%' . $key . '$e', $str);
    } 
    $str = htmlspecialchars($str, ENT_FLAGS, LOCAL_CHARSET);
    foreach (array_reverse($tags, true) as $taglist) {
        $str = strtr($str, $taglist);
    }
    if ($str != $original) {
        $str = tidyHTML($str);
    }
    return $str;
}
function html_pathurlencode($url) {
    return html_encode(pathurlencode($url));
}
function mkdir_recursive($pathname, $mode) {
    if (!is_dir(dirname($pathname))) {
        mkdir_recursive(dirname($pathname), $mode);
    }
    return is_dir($pathname) || @mkdir($pathname, $mode);
}
function debugLogBacktrace($message, $omit = 0) {
    $output = trim($message) . "\n";
    
    $bt = debug_backtrace();
    while ($omit >= 0) {
        array_shift($bt); 
        $omit--;
    }
    $prefix = '  ';
    $line = '';
    $caller = '';
    foreach ($bt as $b) {
        $caller = (isset($b['class']) ? $b['class'] : '') . (isset($b['type']) ? $b['type'] : '') . $b['function'];
        if (!empty($line)) { 
            $prefix .= '  ';
            $output .= 'from ' . $caller . ' (' . $line . ")\n" . $prefix;
        } else {
            $output .= '  ' . $caller . " called ";
        }
        $date = false;
        if (isset($b['file']) && isset($b['line'])) {
            $line = basename($b['file']) . ' [' . $b['line'] . "]";
        } else {
            $line = 'unknown';
        }
    }
    if (!empty($line)) {
        $output .= 'from ' . $line;
    }
    debugLog($output);
}
function debugLogVar($message) {
    $args = func_get_args();
    if (count($args) == 1) {
        $var = $message;
        $message = '';
    } else {
        $message .= ' ';
        $var = $args[1];
    }
    ob_start();
    var_dump($var);
    $str = ob_get_contents();
    ob_end_clean();
    debugLog(trim($message) . "\r" . html_decode(getBare($str)));
}
function zp_getCookie($name) {
  if (isset($_COOKIE[$name])) {
    $cookiev = sanitize($_COOKIE[$name]);
  } else {
    $cookiev = '';
  }
  if (DEBUG_LOGIN) {
    if (isset($_SESSION[$name])) {
      $sessionv = sanitize($_SESSION[$name]);
    } else {
      $sessionv = '';
    }
    debugLog(zp_getCookie($name) . '=::' . 'album_session=' . GALLERY_SESSION . "; SESSION[" . session_id() . "]=" . sanitize($sessionv) . ", COOKIE=" . sanitize($cookiev));
  }
  if (!empty($cookiev) && (defined('GALLERY_SESSION') && !GALLERY_SESSION)) {
    return zp_cookieEncode($cookiev);
  }
  if (isset($_SESSION[$name])) {
    return sanitize($_SESSION[$name]);
  }
  return NULL;
}
function zp_cookieEncode($value) {
    if (IP_TIED_COOKIES) {
        return rc4(getUserIP() . HASH_SEED, $value);
    } else {
        return $value;
    }
}
function zp_setCookie($name, $value, $time = NULL, $path = NULL, $secure = false, $httponly = false) {
  if (empty($value)) {
    $cookiev = '';
  } else {
    $cookiev = zp_cookieEncode(sanitize($value));
  }
  if (is_null($time)) {
    $time = COOKIE_PERSISTENCE;
  }
  if (is_null($path)) {
    $path = WEBPATH;
  }
  if (substr($path, -1, 1) != '/')
    $path .= '/';
  if (DEBUG_LOGIN) {
    debugLog("zp_setCookie($name, $value, $time, $path)::album_session=" . GALLERY_SESSION . "; SESSION=" . session_id());
  }
  if (($time < 0) || !GALLERY_SESSION) {
        if (version_compare(PHP_VERSION, '7.3.0', '>=')) {
            $options = array(
                    'expires' => (time() + $time),
                    'path' => $path,
                    'secure' => $secure,
                    'httponly' => $httponly,
                    'samesite' => 'Lax'
            );
            setcookie($name, $cookiev, $options);
        } else {
            setcookie($name, $cookiev, time() + $time, $path, '', $secure, $httponly);
        }
    }
    if ($time < 0) {
    if (isset($_SESSION))
      unset($_SESSION[$name]);
    if (isset($_COOKIE))
      unset($_COOKIE[$name]);
  } else {
    $_SESSION[$name] = sanitize($value);
    $_COOKIE[$name] = sanitize($cookiev);
  }
}
function zp_clearCookie($name, $path = NULl, $secure = false, $httponly = false) {
    zp_setCookie($name, '', -368000, $path, $secure, $httponly);
}
function getSerializedArray($string) {
    if (is_array($string)) {
        return $string;
    }
    if (preg_match('/^a:[0-9]+:{/', $string)) {
        $r = @unserialize($string);
        if ($r) {
            return $r;
        } else {
            return array();
        }
    } else if (strlen($string) == 0 && !is_bool($string)) {
        return array();
    } else {
        return array($string);
    }
}
?>