Return');// block any attempt to explore the filesystem - check if images are included in the "images" folder$ref_com_content = $siteUrl.'/'.substr($_GET['file'],0,strlen('images/'));$check_com_content = $siteUrl."/images/";$ref_com_k2 = $siteUrl.'/'.substr($_GET['file'],0,strlen('media/k2/videos/'));$check_com_k2 = $siteUrl."/media/k2/videos/";if( isset($_GET['file']) && ($ref_com_content===$check_com_content || $ref_com_k2===$check_com_k2)){$getfile = $_GET['file'];} else {$getfile = NULL;}if (!$getfile) {// go no further if filename not setecho $nogo;} else {// define the pathname to the file$filepath = $sitePath.DS.$getfile;// check that it exists and is readableif (file_exists($filepath) && is_readable($filepath)) {// get the file's size and send the appropriate headers$size = filesize($filepath);header('Content-Type: application/force-download');header('Content-Length: '.$size);header('Content-Disposition: attachment; filename="'.basename($getfile).'"');header('Content-Transfer-Encoding: binary');// open the file in binary read-only mode// suppress error messages if the file can't be opened$file = @ fopen($filepath, 'rb');if ($file) {// stream the file and exit the script when completefpassthru($file);exit;} else {echo $nogo;}} else {echo $nogo;}}