$album = array_key_exists("album",$_GET) ? preg_replace("/[\/\\\]/","",str_replace("..","",$_GET["album"])) : ''; if ($album == '') { header("location: /list"); die(); } $files = array(); if ($handle = opendir('albums/'.$album)) { while (false !== ($file = readdir($handle))) { if ($file != "." && $file != ".." && strtolower(substr($file,-4))==".jpg") { $files[] = $file; } } closedir($handle); } sort($files); ?> print "\n"; ?>