📁
SKYSHELL MANAGER
PHP v8.1.29
Create
Create
Path:
root
/
var
/
www
/
html
/
wxwpsite
/
fungiftdeals
/
wp-admin
/
Name
Size
Perm
Actions
📁
css
-
0755
🗑️
🏷️
🔒
📁
images
-
0755
🗑️
🏷️
🔒
📁
includes
-
0755
🗑️
🏷️
🔒
📁
js
-
0755
🗑️
🏷️
🔒
📁
maint
-
0755
🗑️
🏷️
🔒
📁
network
-
0755
🗑️
🏷️
🔒
📁
user
-
0755
🗑️
🏷️
🔒
📄
about.php
6.83 KB
0444
🗑️
🏷️
⬇️
✏️
🔒
📄
admin-footer.php
2.75 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
admin.php
12.63 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
async-upload.php
5.47 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
authorize-application.php
10.09 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
comment.php
11.37 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
config.php
6.83 KB
0444
🗑️
🏷️
⬇️
✏️
🔒
📄
custom-header.php
0.49 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
customize.php
11.21 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
data.php
6.83 KB
0444
🗑️
🏷️
⬇️
✏️
🔒
📄
edit-form-blocks.php
14.73 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
edit.php
19.48 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
export-personal-data.php
7.75 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
font-library.php
1.01 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
home.php
6.83 KB
0444
🗑️
🏷️
⬇️
✏️
🔒
📄
index.php
7.68 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
media-upload.php
3.58 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
menu-header.php
9.82 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
network.php
5.39 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
press-this.php
2.41 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
privacy.php
2.83 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
setup-config.php
17.52 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
themes.phpwp-update.php
114.83 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
update.php
12.76 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
user-edit.php
40.35 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
widgets-form-blocks.php
5.12 KB
0644
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-mail.php
6.83 KB
0444
🗑️
🏷️
⬇️
✏️
🔒
📄
xmlrpc.php
6.83 KB
0444
🗑️
🏷️
⬇️
✏️
🔒
Edit: attr.go
// Copyright 2011 The Go Authors. All rights reserved. // Use of this source code is governed by a BSD-style // license that can be found in the LICENSE file. package template import ( "strings" ) // attrTypeMap[n] describes the value of the given attribute. // If an attribute affects (or can mask) the encoding or interpretation of // other content, or affects the contents, idempotency, or credentials of a // network message, then the value in this map is contentTypeUnsafe. // This map is derived from HTML5, specifically // https://www.w3.org/TR/html5/Overview.html#attributes-1 // as well as "%URI"-typed attributes from // https://www.w3.org/TR/html4/index/attributes.html var attrTypeMap = map[string]contentType{ "accept": contentTypePlain, "accept-charset": contentTypeUnsafe, "action": contentTypeURL, "alt": contentTypePlain, "archive": contentTypeURL, "async": contentTypeUnsafe, "autocomplete": contentTypePlain, "autofocus": contentTypePlain, "autoplay": contentTypePlain, "background": contentTypeURL, "border": contentTypePlain, "checked": contentTypePlain, "cite": contentTypeURL, "challenge": contentTypeUnsafe, "charset": contentTypeUnsafe, "class": contentTypePlain, "classid": contentTypeURL, "codebase": contentTypeURL, "cols": contentTypePlain, "colspan": contentTypePlain, "content": contentTypeUnsafe, "contenteditable": contentTypePlain, "contextmenu": contentTypePlain, "controls": contentTypePlain, "coords": contentTypePlain, "crossorigin": contentTypeUnsafe, "data": contentTypeURL, "datetime": contentTypePlain, "default": contentTypePlain, "defer": contentTypeUnsafe, "dir": contentTypePlain, "dirname": contentTypePlain, "disabled": contentTypePlain, "draggable": contentTypePlain, "dropzone": contentTypePlain, "enctype": contentTypeUnsafe, "for": contentTypePlain, "form": contentTypeUnsafe, "formaction": contentTypeURL, "formenctype": contentTypeUnsafe, "formmethod": contentTypeUnsafe, "formnovalidate": contentTypeUnsafe, "formtarget": contentTypePlain, "headers": contentTypePlain, "height": contentTypePlain, "hidden": contentTypePlain, "high": contentTypePlain, "href": contentTypeURL, "hreflang": contentTypePlain, "http-equiv": contentTypeUnsafe, "icon": contentTypeURL, "id": contentTypePlain, "ismap": contentTypePlain, "keytype": contentTypeUnsafe, "kind": contentTypePlain, "label": contentTypePlain, "lang": contentTypePlain, "language": contentTypeUnsafe, "list": contentTypePlain, "longdesc": contentTypeURL, "loop": contentTypePlain, "low": contentTypePlain, "manifest": contentTypeURL, "max": contentTypePlain, "maxlength": contentTypePlain, "media": contentTypePlain, "mediagroup": contentTypePlain, "method": contentTypeUnsafe, "min": contentTypePlain, "multiple": contentTypePlain, "name": contentTypePlain, "novalidate": contentTypeUnsafe, // Skip handler names from // https://www.w3.org/TR/html5/webappapis.html#event-handlers-on-elements,-document-objects,-and-window-objects // since we have special handling in attrType. "open": contentTypePlain, "optimum": contentTypePlain, "pattern": contentTypeUnsafe, "placeholder": contentTypePlain, "poster": contentTypeURL, "profile": contentTypeURL, "preload": contentTypePlain, "pubdate": contentTypePlain, "radiogroup": contentTypePlain, "readonly": contentTypePlain, "rel": contentTypeUnsafe, "required": contentTypePlain, "reversed": contentTypePlain, "rows": contentTypePlain, "rowspan": contentTypePlain, "sandbox": contentTypeUnsafe, "spellcheck": contentTypePlain, "scope": contentTypePlain, "scoped": contentTypePlain, "seamless": contentTypePlain, "selected": contentTypePlain, "shape": contentTypePlain, "size": contentTypePlain, "sizes": contentTypePlain, "span": contentTypePlain, "src": contentTypeURL, "srcdoc": contentTypeHTML, "srclang": contentTypePlain, "srcset": contentTypeSrcset, "start": contentTypePlain, "step": contentTypePlain, "style": contentTypeCSS, "tabindex": contentTypePlain, "target": contentTypePlain, "title": contentTypePlain, "type": contentTypeUnsafe, "usemap": contentTypeURL, "value": contentTypeUnsafe, "width": contentTypePlain, "wrap": contentTypePlain, "xmlns": contentTypeURL, } // attrType returns a conservative (upper-bound on authority) guess at the // type of the lowercase named attribute. func attrType(name string) contentType { if strings.HasPrefix(name, "data-") { // Strip data- so that custom attribute heuristics below are // widely applied. // Treat data-action as URL below. name = name[5:] } else if prefix, short, ok := strings.Cut(name, ":"); ok { if prefix == "xmlns" { return contentTypeURL } // Treat svg:href and xlink:href as href below. name = short } if t, ok := attrTypeMap[name]; ok { return t } // Treat partial event handler names as script. if strings.HasPrefix(name, "on") { return contentTypeJS } // Heuristics to prevent "javascript:..." injection in custom // data attributes and custom attributes like g:tweetUrl. // https://www.w3.org/TR/html5/dom.html#embedding-custom-non-visible-data-with-the-data-*-attributes // "Custom data attributes are intended to store custom data // private to the page or application, for which there are no // more appropriate attributes or elements." // Developers seem to store URL content in data URLs that start // or end with "URI" or "URL". if strings.Contains(name, "src") || strings.Contains(name, "uri") || strings.Contains(name, "url") { return contentTypeURL } return contentTypePlain }
Save