diff -c -rNbB attach_mod_235/admin/admin_extensions.php attach_mod_236/admin/admin_extensions.php
*** attach_mod_235/admin/admin_extensions.php	Mon Feb  3 15:37:27 2003
--- attach_mod_236/admin/admin_extensions.php	Mon Feb  3 15:37:22 2003
***************
*** 6,12 ****
   *   copyright            : (C) 2002 Meik Sievertsen
   *   email                : acyd.burn@gmx.de
   *
!  *   $Id: admin_extensions.php,v 1.18 2003/01/15 23:24:26 acydburn Exp $
   *
   ***************************************************************************/
  
--- 6,12 ----
   *   copyright            : (C) 2002 Meik Sievertsen
   *   email                : acyd.burn@gmx.de
   *
!  *   $Id: admin_extensions.php,v 1.19 2003/01/26 12:23:20 acydburn Exp $
   *
   ***************************************************************************/
  
***************
*** 746,752 ****
  
  	$sql = "SELECT *
  	FROM " . FORBIDDEN_EXTENSIONS_TABLE . "
! 	ORDER BY 'extension'";
  	
  	if ( !($result = $db->sql_query($sql)) )
  	{
--- 746,752 ----
  
  	$sql = "SELECT *
  	FROM " . FORBIDDEN_EXTENSIONS_TABLE . "
! 	ORDER BY extension";
  	
  	if ( !($result = $db->sql_query($sql)) )
  	{
diff -c -rNbB attach_mod_235/attach_mod/attach_rules.php attach_mod_236/attach_mod/attach_rules.php
*** attach_mod_235/attach_mod/attach_rules.php	Mon Feb  3 15:37:27 2003
--- attach_mod_236/attach_mod/attach_rules.php	Mon Feb  3 15:37:22 2003
***************
*** 6,12 ****
   *   copyright            : (C) 2002 Meik Sievertsen
   *   email                : acyd.burn@gmx.de
   *
!  *   $Id: attach_rules.php,v 1.9 2003/01/15 23:24:26 acydburn Exp $
   *
   *
   ***************************************************************************/
--- 6,12 ----
   *   copyright            : (C) 2002 Meik Sievertsen
   *   email                : acyd.burn@gmx.de
   *
!  *   $Id: attach_rules.php,v 1.10 2003/01/18 16:02:10 acydburn Exp $
   *
   *
   ***************************************************************************/
***************
*** 53,59 ****
  // 
  if ($privmsg)
  {
! 	$auth['auth_attachments'] = intval($attach_config['allow_pm_attach']);
  	$auth['auth_view'] = TRUE;
  }
  else
--- 53,59 ----
  // 
  if ($privmsg)
  {
! 	$auth['auth_attachments'] = ($userdata['user_level'] != ADMIN) ? intval($attach_config['allow_pm_attach']) : TRUE;
  	$auth['auth_view'] = TRUE;
  }
  else
diff -c -rNbB attach_mod_235/attach_mod/displaying.php attach_mod_236/attach_mod/displaying.php
*** attach_mod_235/attach_mod/displaying.php	Mon Feb  3 15:37:27 2003
--- attach_mod_236/attach_mod/displaying.php	Mon Feb  3 15:37:22 2003
***************
*** 6,12 ****
   *   copyright            : (C) 2002 Meik Sievertsen
   *   email                : acyd.burn@gmx.de
   *
!  *   $Id: displaying.php,v 1.41 2003/01/15 23:24:26 acydburn Exp $
   *
   *
   ***************************************************************************/
--- 6,12 ----
   *   copyright            : (C) 2002 Meik Sievertsen
   *   email                : acyd.burn@gmx.de
   *
!  *   $Id: displaying.php,v 1.43 2003/02/01 03:07:24 acydburn Exp $
   *
   *
   ***************************************************************************/
***************
*** 420,426 ****
  	
  		// Another 'i have to fix minor phpBB2 Bugs...' patch
  		$template->assign_vars(array(
! 			'T_BODY_TEXT' => '#'.$theme['body_text'])
  		);
  
  		for ($i = 0; $i < count($attachment_list); $i++)
--- 420,427 ----
  	
  		// Another 'i have to fix minor phpBB2 Bugs...' patch
  		$template->assign_vars(array(
! 			'T_BODY_TEXT' => '#'.$theme['body_text'],
! 			'T_TR_COLOR3' => '#'.$theme['tr_color3'])
  		);
  
  		for ($i = 0; $i < count($attachment_list); $i++)
***************
*** 761,766 ****
--- 762,772 ----
  			{
  				//
  				// Images
+ 				// NOTE: If you want to use the download.php everytime an image is displayed inlined, replace the
+ 				// Section between BEGIN and END with (Without the // of course):
+ 				//	$img_source = append_sid('download.' . $phpEx . '?id=' . $attachments['_' . $post_id][$i]['attach_id']);
+ 				//	$download_link = TRUE;
+ 				// 
  				//
  				if ((intval($attach_config['allow_ftp_upload'])) && (trim($attach_config['download_path']) == ''))
  				{
***************
*** 805,810 ****
--- 811,819 ----
  			{
  				//
  				// Images, but display Thumbnail
+ 				// NOTE: If you want to use the download.php everytime an thumnmail is displayed inlined, replace the
+ 				// Section between BEGIN and END with (Without the // of course):
+ 				//	$thumb_source = append_sid('download.' . $phpEx . '?id=' . $attachments['_' . $post_id][$i]['attach_id'] . '&thumb=1');
  				//
  				if ( (intval($attach_config['allow_ftp_upload'])) && (trim($attach_config['download_path']) == '') )
  				{
diff -c -rNbB attach_mod_235/attach_mod/includes/constants.php attach_mod_236/attach_mod/includes/constants.php
*** attach_mod_235/attach_mod/includes/constants.php	Mon Feb  3 15:37:27 2003
--- attach_mod_236/attach_mod/includes/constants.php	Mon Feb  3 15:37:22 2003
***************
*** 6,12 ****
   *   copyright            : (C) 2002 Meik Sievertsen
   *   email                : acyd.burn@gmx.de
   *
!  *   $Id: constants.php,v 1.20 2003/01/16 11:11:56 acydburn Exp $
   *
   *
   ***************************************************************************/
--- 6,12 ----
   *   copyright            : (C) 2002 Meik Sievertsen
   *   email                : acyd.burn@gmx.de
   *
!  *   $Id: constants.php,v 1.21 2003/01/29 13:26:50 acydburn Exp $
   *
   *
   ***************************************************************************/
***************
*** 72,77 ****
  define('QUOTA_UPLOAD_LIMIT', 1);
  define('QUOTA_PM_LIMIT', 2);
  
! define('ATTACH_VERSION', '2.3.5');
  
  ?>
\ No newline at end of file
--- 72,77 ----
  define('QUOTA_UPLOAD_LIMIT', 1);
  define('QUOTA_PM_LIMIT', 2);
  
! define('ATTACH_VERSION', '2.3.6');
  
  ?>
\ No newline at end of file
diff -c -rNbB attach_mod_235/attach_mod/includes/functions_admin.php attach_mod_236/attach_mod/includes/functions_admin.php
*** attach_mod_235/attach_mod/includes/functions_admin.php	Mon Feb  3 15:37:27 2003
--- attach_mod_236/attach_mod/includes/functions_admin.php	Mon Feb  3 15:37:22 2003
***************
*** 6,12 ****
   *   copyright            : (C) 2002 Meik Sievertsen
   *   email                : acyd.burn@gmx.de
   *
!  *   $Id: functions_admin.php,v 1.11 2003/01/16 10:48:15 acydburn Exp $
   *
   *
   ***************************************************************************/
--- 6,12 ----
   *   copyright            : (C) 2002 Meik Sievertsen
   *   email                : acyd.burn@gmx.de
   *
!  *   $Id: functions_admin.php,v 1.13 2003/01/28 16:32:31 acydburn Exp $
   *
   *
   ***************************************************************************/
***************
*** 241,247 ****
  		}
  		else
  		{
! 			message_dir(GENERAL_ERROR, 'Is Safe Mode Restriction in effect ? The Attachment Mod seems to be unable to collect the Attachments within the upload Directory. Try to use FTP Upload to circumvent this error.');
  		}
  	}
  	else
--- 241,247 ----
  		}
  		else
  		{
! 			message_die(GENERAL_ERROR, 'Is Safe Mode Restriction in effect ? The Attachment Mod seems to be unable to collect the Attachments within the upload Directory. Try to use FTP Upload to circumvent this error.');
  		}
  	}
  	else
***************
*** 250,256 ****
  
  		$file_listing = array();
  
! 		$file_listing = @ftp_rawlist($conn_id, './');
  
  		for ($i = 0; $i < count($file_listing); $i++)
  		{
--- 250,261 ----
  
  		$file_listing = array();
  
! 		$file_listing = @ftp_rawlist($conn_id, '');
! 
! 		if (!$file_listing)
! 		{
! 			message_die(GENERAL_ERROR, 'Unable to get Raw File Listing. Please be sure the LIST command is enabled at your FTP Server.');
! 		}
  
  		for ($i = 0; $i < count($file_listing); $i++)
  		{
***************
*** 313,319 ****
  
  		$file_listing = array();
  
! 		$file_listing = @ftp_rawlist($conn_id, './');
  
  		if (!$file_listing)
  		{
--- 318,324 ----
  
  		$file_listing = array();
  
! 		$file_listing = @ftp_rawlist($conn_id, '');
  
  		if (!$file_listing)
  		{
diff -c -rNbB attach_mod_235/attach_mod/includes/functions_attach.php attach_mod_236/attach_mod/includes/functions_attach.php
*** attach_mod_235/attach_mod/includes/functions_attach.php	Mon Feb  3 15:37:27 2003
--- attach_mod_236/attach_mod/includes/functions_attach.php	Mon Feb  3 15:37:22 2003
***************
*** 6,12 ****
   *   copyright            : (C) 2002 Meik Sievertsen
   *   email                : acyd.burn@gmx.de
   *
!  *   $Id: functions_attach.php,v 1.31 2003/01/15 23:24:26 acydburn Exp $
   *
   *
   ***************************************************************************/
--- 6,12 ----
   *   copyright            : (C) 2002 Meik Sievertsen
   *   email                : acyd.burn@gmx.de
   *
!  *   $Id: functions_attach.php,v 1.33 2003/02/01 03:09:46 acydburn Exp $
   *
   *
   ***************************************************************************/
***************
*** 195,203 ****
  {
  	global $lang, $attach_config;
  
! 	$server = ( $attach_config['ftp_server'] == '' ) ? 'localhost' : $attach_config['ftp_server'];
  	
! 	$ftp_path = ( $mode == MODE_THUMBNAIL ) ? $attach_config['ftp_path'] . '/' . THUMB_DIR : $attach_config['ftp_path'];
  
  	$conn_id = @ftp_connect($server);
  
--- 195,203 ----
  {
  	global $lang, $attach_config;
  
! 	$server = ( trim($attach_config['ftp_server']) == '' ) ? 'localhost' : trim($attach_config['ftp_server']);
  	
! 	$ftp_path = ( $mode == MODE_THUMBNAIL ) ? trim($attach_config['ftp_path']) . '/' . THUMB_DIR : trim($attach_config['ftp_path']);
  
  	$conn_id = @ftp_connect($server);
  
***************
*** 794,800 ****
  {
  	$extension = strrchr(strtolower($filename), '.');
  	$extension[0] = ' ';
! 	return (strtolower(trim($extension)));
  }
  
  //
--- 794,808 ----
  {
  	$extension = strrchr(strtolower($filename), '.');
  	$extension[0] = ' ';
! 	$extension = strtolower(trim($extension));
! 	if (is_array($extension))
! 	{
! 		return ('');
! 	}
! 	else
! 	{
! 		return ($extension);
! 	}
  }
  
  //
diff -c -rNbB attach_mod_235/attach_mod/includes/functions_delete.php attach_mod_236/attach_mod/includes/functions_delete.php
*** attach_mod_235/attach_mod/includes/functions_delete.php	Mon Feb  3 15:37:27 2003
--- attach_mod_236/attach_mod/includes/functions_delete.php	Mon Feb  3 15:37:22 2003
***************
*** 6,12 ****
   *   copyright            : (C) 2002 Meik Sievertsen
   *   email                : acyd.burn@gmx.de
   *
!  *   $Id: functions_delete.php,v 1.6 2003/01/15 23:24:26 acydburn Exp $
   *
   *
   ***************************************************************************/
--- 6,12 ----
   *   copyright            : (C) 2002 Meik Sievertsen
   *   email                : acyd.burn@gmx.de
   *
!  *   $Id: functions_delete.php,v 1.9 2003/01/22 11:25:49 acydburn Exp $
   *
   *
   ***************************************************************************/
***************
*** 46,53 ****
  
  		if (!is_array($attach_id_array))
  		{
  			$attach_id = intval($attach_id_array);
- 
  			$attach_id_array = array();
  			$attach_id_array[] = $attach_id;
  		}
--- 46,62 ----
  
  		if (!is_array($attach_id_array))
  		{
+ 			if (strstr($attach_id_array, ', '))
+ 			{
+ 				$attach_id_array = explode(', ', $attach_id_array);
+ 			}
+ 			else if (strstr($attach_id_array, ','))
+ 			{
+ 				$attach_id_array = explode(',', $attach_id_array);
+ 			}
+ 			else
+ 			{
  				$attach_id = intval($attach_id_array);
  				$attach_id_array = array();
  				$attach_id_array[] = $attach_id;
  			}
***************
*** 51,56 ****
--- 60,66 ----
  				$attach_id_array = array();
  				$attach_id_array[] = $attach_id;
  			}
+ 		}
  	
  		// Get the post_ids to fill the array
  		if ($page == PAGE_PRIVMSGS)
***************
*** 73,101 ****
  		$post_list = $db->sql_fetchrowset($result);
  		$num_post_list = $db->sql_numrows($result);
  
! 		for ($i = 0; $i < $num_post_list; $i++)
  		{
! 			$post_id_array[] = $post_list[$i][$p_id];
  		}
  
! 		if ($num_post_list == 0)
  		{
! 			return;
  		}
  	}
  		
  	if (!is_array($post_id_array))
  	{
! 		if (empty($post_id_array))
  		{
  			return;
  		}
  
  		$post_id = intval($post_id_array);
  
  		$post_id_array = array();
  		$post_id_array[] = $post_id;
  	}
  		
  	if (count($post_id_array) == 0)
  	{
--- 83,122 ----
  		$post_list = $db->sql_fetchrowset($result);
  		$num_post_list = $db->sql_numrows($result);
  
! 		if ($num_post_list == 0)
  		{
! 			return;
  		}
  
! 		for ($i = 0; $i < $num_post_list; $i++)
  		{
! 			$post_id_array[] = intval($post_list[$i][$p_id]);
  		}
  	}
  		
  	if (!is_array($post_id_array))
  	{
! 		if (trim($post_id_array) == '')
  		{
  			return;
  		}
  
+ 		if (strstr($post_id_array, ', '))
+ 		{
+ 			$post_id_array = explode(', ', $post_id_array);
+ 		}
+ 		else if (strstr($post_id_array, ','))
+ 		{
+ 			$post_id_array = explode(',', $post_id_array);
+ 		}
+ 		else
+ 		{
  			$post_id = intval($post_id_array);
  
  			$post_id_array = array();
  			$post_id_array[] = $post_id;
  		}
+ 	}
  		
  	if (count($post_id_array) == 0)
  	{
***************
*** 129,152 ****
  		$attach_list = $db->sql_fetchrowset($result);
  		$num_attach_list = $db->sql_numrows($result);
  
! 		for ($i = 0; $i < $num_attach_list; $i++)
  		{
! 			$attach_id_array[] = $attach_list[$i]['attach_id'];
  		}
  
! 		if ($num_attach_list == 0)
  		{
! 			return;
  		}
  	}
  	
  	if (!is_array($attach_id_array))
  	{
  		$attach_id = intval($attach_id_array);
  
  		$attach_id_array = array();
  		$attach_id_array[] = $attach_id;
  	}
  
  	if (count($attach_id_array) == 0)
  	{
--- 150,184 ----
  		$attach_list = $db->sql_fetchrowset($result);
  		$num_attach_list = $db->sql_numrows($result);
  
! 		if ($num_attach_list == 0)
  		{
! 			return;
  		}
  
! 		for ($i = 0; $i < $num_attach_list; $i++)
  		{
! 			$attach_id_array[] = intval($attach_list[$i]['attach_id']);
  		}
  	}
  	
  	if (!is_array($attach_id_array))
  	{
+ 		if (strstr($attach_id_array, ', '))
+ 		{
+ 			$attach_id_array = explode(', ', $attach_id_array);
+ 		}
+ 		else if (strstr($attach_id_array, ','))
+ 		{
+ 			$attach_id_array = explode(',', $attach_id_array);
+ 		}
+ 		else
+ 		{
  			$attach_id = intval($attach_id_array);
  
  			$attach_id_array = array();
  			$attach_id_array[] = $attach_id;
  		}
+ 	}
  
  	if (count($attach_id_array) == 0)
  	{
***************
*** 162,168 ****
  		$sql_id = 'post_id';
  	}
  
! 	$sql = "DELETE FROM " . ATTACHMENTS_TABLE . " WHERE attach_id IN (" . implode(', ', $attach_id_array) . ") AND " . $sql_id . " IN (" . implode(', ', $post_id_array) . ")";          $delete_attachment_sql = "DELETE FROM " . ATTACHMENTS_TABLE . " WHERE attach_id IN (" . implode(', ', $attach_id_array) . ") AND " . $sql_id . " IN (" . implode(', ', $post_id_array) . ")"; 
      
  	if ( !(attach_sql_query($sql)) )   
  	{   
--- 194,200 ----
  		$sql_id = 'post_id';
  	}
  
! 	$sql = "DELETE FROM " . ATTACHMENTS_TABLE . " WHERE attach_id IN (" . implode(', ', $attach_id_array) . ") AND " . $sql_id . " IN (" . implode(', ', $post_id_array) . ")";
      
  	if ( !(attach_sql_query($sql)) )   
  	{
diff -c -rNbB attach_mod_235/attach_mod/includes/functions_includes.php attach_mod_236/attach_mod/includes/functions_includes.php
*** attach_mod_235/attach_mod/includes/functions_includes.php	Mon Feb  3 15:37:27 2003
--- attach_mod_236/attach_mod/includes/functions_includes.php	Mon Feb  3 15:37:22 2003
***************
*** 6,12 ****
   *   copyright            : (C) 2002 Meik Sievertsen
   *   email                : acyd.burn@gmx.de
   *
!  *   $Id: functions_includes.php,v 1.20 2003/01/17 09:29:45 acydburn Exp $
   *
   *
   ***************************************************************************/
--- 6,12 ----
   *   copyright            : (C) 2002 Meik Sievertsen
   *   email                : acyd.burn@gmx.de
   *
!  *   $Id: functions_includes.php,v 1.27 2003/01/30 12:47:35 acydburn Exp $
   *
   *
   ***************************************************************************/
***************
*** 242,281 ****
  //
  function attachment_quota_settings($admin_mode, $submit = FALSE, $mode)
  {
! 	global $template, $db, $HTTP_POST_VARS, $lang, $group_id;
  
  	if ($admin_mode == 'user')
  	{
  		if (!$submit && $mode != 'save')
  		{
! 			if( isset( $HTTP_GET_VARS[POST_USERS_URL]) || isset( $HTTP_POST_VARS[POST_USERS_URL]) )
  			{
! 				$user_id = ( isset( $HTTP_POST_VARS[POST_USERS_URL]) ) ? intval( $HTTP_POST_VARS[POST_USERS_URL]) : intval( $HTTP_GET_VARS[POST_USERS_URL]);
! 				$this_userdata = get_userdata($user_id);
! 				if( !$this_userdata )
  				{
! 					return;
  				}
  			}
  			else
  			{
! 				$this_userdata = get_userdata( $HTTP_POST_VARS['username'] );
  				if( !$this_userdata )
  				{
! 					return;
  				}
  			}
  
! 			$user_id = $this_userdata['user_id'];
  		}
  		else
  		{
! 			$user_id = intval( $HTTP_POST_VARS['id'] );
  
! 			$this_userdata = get_userdata($user_id);
! 			if( !$this_userdata )
  			{
! 				return;
  			}
  		}
  	}
--- 242,283 ----
  //
  function attachment_quota_settings($admin_mode, $submit = FALSE, $mode)
  {
! 	global $template, $db, $HTTP_POST_VARS, $HTTP_GET_VARS, $lang, $group_id, $lang;
  
  	if ($admin_mode == 'user')
  	{
+ 		$submit = (isset($HTTP_POST_VARS['submit'])) ? TRUE : FALSE;
+ 
  		if (!$submit && $mode != 'save')
  		{
! 			if ( isset($HTTP_GET_VARS[POST_USERS_URL]) || isset($HTTP_POST_VARS[POST_USERS_URL]) )
  			{
! 				$user_id = (isset($HTTP_POST_VARS[POST_USERS_URL])) ? intval($HTTP_POST_VARS[POST_USERS_URL]) : intval($HTTP_GET_VARS[POST_USERS_URL]);
! 				$this_userdata['user_id'] = $user_id;
! 				if (empty($user_id))
  				{
! 					message_die(GENERAL_MESSAGE, $lang['No_user_id_specified'] );
  				}
  			}
  			else
  			{
! 				$u_name = (isset($HTTP_POST_VARS['username'])) ? htmlspecialchars(trim($HTTP_POST_VARS['username'])) : htmlspecialchars(trim($HTTP_GET_VARS['username']));
! 				$this_userdata = get_userdata($u_name);
  				if( !$this_userdata )
  				{
! 					message_die(GENERAL_MESSAGE, $lang['No_user_id_specified'] );
  				}
  			}
  		
! 			$user_id = intval($this_userdata['user_id']);
  		}
  		else
  		{
! 			$user_id = (isset($HTTP_POST_VARS['id'])) ? intval($HTTP_POST_VARS['id']) : intval($HTTP_GET_VARS['id']);
  			
! 			if ( empty($user_id) )
  			{
! 				message_die(GENERAL_MESSAGE, $lang['No_user_id_specified'] );
  			}
  		}
  	}
***************
*** 347,352 ****
--- 349,367 ----
  	{
  		return;
  	}
+ 	else if ($admin_mode == 'group')
+ 	{
+ 		// Get group id again, we do not trust phpBB here, Mods may be installed ;)
+ 		if ( isset($HTTP_POST_VARS[POST_GROUPS_URL]) || isset($HTTP_GET_VARS[POST_GROUPS_URL]) )
+ 		{
+ 			$group_id = ( isset($HTTP_POST_VARS[POST_GROUPS_URL]) ) ? intval($HTTP_POST_VARS[POST_GROUPS_URL]) : intval($HTTP_GET_VARS[POST_GROUPS_URL]);
+ 		}
+ 		else
+ 		{
+ 			// This should not occur :(
+ 			$group_id = '';
+ 		}
+ 	}
  
  	if ($admin_mode == 'group' && !$submit && isset($HTTP_POST_VARS['edit']))
  	{
***************
*** 419,425 ****
  //
  function display_upload_attach_box_limits($user_id, $group_id = -1)
  {
! 	global $attach_config, $board_config, $phpbb_root_path, $lang, $db, $template, $phpEx, $userdata;
  	
  	if (($userdata['user_level'] != ADMIN) && ($userdata['user_id'] != $user_id))
  	{
--- 434,440 ----
  //
  function display_upload_attach_box_limits($user_id, $group_id = -1)
  {
! 	global $attach_config, $board_config, $phpbb_root_path, $lang, $db, $template, $phpEx, $userdata, $profiledata;
  	
  	if (($userdata['user_level'] != ADMIN) && ($userdata['user_id'] != $user_id))
  	{
***************
*** 489,495 ****
  	}
  	else
  	{
! 		$attachments->get_quota_limits($user_id);
  	}
  
  	if ( intval($attach_config['upload_filesize_limit']) == 0 )
--- 504,517 ----
  	}
  	else
  	{
! 		if (is_array($profiledata))
! 		{
! 			$attachments->get_quota_limits($profiledata, $user_id);
! 		}
! 		else
! 		{
! 			$attachments->get_quota_limits($userdata, $user_id);
! 		}
  	}
  
  	if ( intval($attach_config['upload_filesize_limit']) == 0 )
***************
*** 564,569 ****
--- 586,595 ----
  
  	$upload_limit_pct = ( $upload_filesize_limit > 0 ) ? round(( $upload_filesize / $upload_filesize_limit ) * 100) : 0;
  	$upload_limit_img_length = ( $upload_filesize_limit > 0 ) ? round(( $upload_filesize / $upload_filesize_limit ) * $board_config['privmsg_graphic_length']) : 0;
+ 	if ($upload_limit_pct > 100)
+ 	{
+ 		$upload_limit_img_length = $board_config['privmsg_graphic_length'];
+ 	}
  	$upload_limit_remain = ( $upload_filesize_limit > 0 ) ? $upload_filesize_limit - $upload_filesize : 100;
  
  	$l_box_size_status = sprintf($lang['Upload_percent_profile'], $upload_limit_pct);
***************
*** 573,579 ****
  	$template->assign_vars(array(
  		'L_UACP' => $lang['UACP'],
  		'L_UPLOAD_QUOTA' => $lang['Upload_quota'],
! 		'U_UACP' => append_sid($phpbb_root_path . 'uacp.' . $phpEx . '?u=' . $user_id),
  		'UPLOADED' => sprintf($lang['User_uploaded_profile'], $user_uploaded),
  		'QUOTA' => sprintf($lang['User_quota_profile'], $user_quota),
  		'UPLOAD_LIMIT_IMG_WIDTH' => $upload_limit_img_length, 
--- 599,605 ----
  	$template->assign_vars(array(
  		'L_UACP' => $lang['UACP'],
  		'L_UPLOAD_QUOTA' => $lang['Upload_quota'],
! 		'U_UACP' => append_sid($phpbb_root_path . 'uacp.' . $phpEx . '?u=' . $user_id . '&amp;sid=' . $userdata['session_id']),
  		'UPLOADED' => sprintf($lang['User_uploaded_profile'], $user_uploaded),
  		'QUOTA' => sprintf($lang['User_quota_profile'], $user_quota),
  		'UPLOAD_LIMIT_IMG_WIDTH' => $upload_limit_img_length, 
diff -c -rNbB attach_mod_235/attach_mod/pm_attachments.php attach_mod_236/attach_mod/pm_attachments.php
*** attach_mod_235/attach_mod/pm_attachments.php	Mon Feb  3 15:37:27 2003
--- attach_mod_236/attach_mod/pm_attachments.php	Mon Feb  3 15:37:22 2003
***************
*** 6,12 ****
   *   copyright            : (C) 2002 Meik Sievertsen
   *   email                : acyd.burn@gmx.de
   *
!  *   $Id: pm_attachments.php,v 1.17 2003/01/17 09:29:45 acydburn Exp $
   *
   *
   ***************************************************************************/
--- 6,12 ----
   *   copyright            : (C) 2002 Meik Sievertsen
   *   email                : acyd.burn@gmx.de
   *
!  *   $Id: pm_attachments.php,v 1.21 2003/01/22 11:33:35 acydburn Exp $
   *
   *
   ***************************************************************************/
***************
*** 114,128 ****
  
  			if ( ($db->sql_numrows($result)) > 0 )
  			{
! 				$row = $db->sql_fetchrow($result);
  		
  				$sql = 'INSERT INTO ' . ATTACHMENTS_TABLE . ' (attach_id, post_id, privmsgs_id, user_id_1, user_id_2) 
! 				VALUES ( ' . $row['attach_id'] . ', ' . $row['post_id'] . ', ' . $new_privmsg_id . ', ' . $row['user_id_1'] . ', ' . $row['user_id_2'] . ')';
  
  				if ( !($result = attach_sql_query($sql)) )
  				{
  					message_die(GENERAL_ERROR, 'Couldn\'t store Attachment for sent Private Message', '', __LINE__, __FILE__, $sql);
  				}
  		
  				$sql = "UPDATE " . PRIVMSGS_TABLE . "
  				SET privmsgs_attachment = 1
--- 114,132 ----
  
  			if ( ($db->sql_numrows($result)) > 0 )
  			{
! 				$rows = $db->sql_fetchrowset($result);
! 				$num_rows = $db->sql_numrows($result);
  
+ 				for ($i = 0; $i < $num_rows; $i++)
+ 				{
  					$sql = 'INSERT INTO ' . ATTACHMENTS_TABLE . ' (attach_id, post_id, privmsgs_id, user_id_1, user_id_2) 
! 					VALUES ( ' . $rows[$i]['attach_id'] . ', ' . $rows[$i]['post_id'] . ', ' . $new_privmsg_id . ', ' . $rows[$i]['user_id_1'] . ', ' . $rows[$i]['user_id_2'] . ')';
  
  					if ( !($result = attach_sql_query($sql)) )
  					{
  						message_die(GENERAL_ERROR, 'Couldn\'t store Attachment for sent Private Message', '', __LINE__, __FILE__, $sql);
  					}
+ 				}
  
  				$sql = "UPDATE " . PRIVMSGS_TABLE . "
  				SET privmsgs_attachment = 1
***************
*** 166,172 ****
  	{
  		global $folder, $attach_config, $board_config, $template, $lang, $userdata, $db;
  
! 		$this->get_quota_limits();
  
  		if ( intval($attach_config['pm_filesize_limit']) == 0 )
  		{
--- 169,175 ----
  	{
  		global $folder, $attach_config, $board_config, $template, $lang, $userdata, $db;
  
! 		$this->get_quota_limits($userdata);
  
  		if ( intval($attach_config['pm_filesize_limit']) == 0 )
  		{
***************
*** 181,186 ****
--- 184,193 ----
  
  		$attach_limit_pct = ( $pm_filesize_limit > 0 ) ? round(( $pm_filesize_total / $pm_filesize_limit ) * 100) : 0;
  		$attach_limit_img_length = ( $pm_filesize_limit > 0 ) ? round(( $pm_filesize_total / $pm_filesize_limit ) * $board_config['privmsg_graphic_length']) : 0;
+ 		if ($attach_limit_pct > 100)
+ 		{
+ 			$attach_limit_img_length = $board_config['privmsg_graphic_length'];
+ 		}
  		$attach_limit_remain = ( $pm_filesize_limit > 0 ) ? $pm_filesize_limit - $pm_filesize_total : 100;
  
  		$l_box_size_status = sprintf($lang['Attachbox_limit'], $attach_limit_pct);
***************
*** 201,214 ****
  		global $attach_config, $template, $lang, $userdata, $HTTP_POST_VARS, $phpbb_root_path, $phpEx, $db;
  		global $confirm, $delete, $delete_all, $post_id, $privmsgs_id, $privmsg_id, $submit, $refresh, $mark_list, $folder;
  
! 		if ( (!intval($attach_config['allow_pm_attach'])) && ($userdata['user_level'] != ADMIN) )
  		{
! 			return;
  		}
  
! 		if ($folder != 'outbox')
  		{
! 			$this->display_attach_box_limits();
  		}
  		
  		if (!$refresh)
--- 208,221 ----
  		global $attach_config, $template, $lang, $userdata, $HTTP_POST_VARS, $phpbb_root_path, $phpEx, $db;
  		global $confirm, $delete, $delete_all, $post_id, $privmsgs_id, $privmsg_id, $submit, $refresh, $mark_list, $folder;
  
! 		if ($folder != 'outbox')
  		{
! 			$this->display_attach_box_limits();
  		}
  
! 		if ( (!intval($attach_config['allow_pm_attach'])) && ($userdata['user_level'] != ADMIN) )
  		{
! 			return;
  		}
  
  		if (!$refresh)
***************
*** 241,247 ****
  			
  			if (count($mark_list))
  			{
! 				$delete_sql_id = implode(', ', $mark_list);
  
  				if ( ( ($this->pm_delete_attachments) || ($confirm) ) && (!$delete_all) )
  				{
--- 248,258 ----
  			
  			if (count($mark_list))
  			{
! 				$delete_sql_id = '';
! 				for ($i = 0; $i < count($mark_list); $i++)
! 				{
! 					$delete_sql_id .= (($delete_sql_id != '') ? ', ' : '') . intval($mark_list[$i]);
! 				}
  
  				if ( ( ($this->pm_delete_attachments) || ($confirm) ) && (!$delete_all) )
  				{
diff -c -rNbB attach_mod_235/attach_mod/posting_attachments.php attach_mod_236/attach_mod/posting_attachments.php
*** attach_mod_235/attach_mod/posting_attachments.php	Mon Feb  3 15:37:27 2003
--- attach_mod_236/attach_mod/posting_attachments.php	Mon Feb  3 15:37:22 2003
***************
*** 6,12 ****
   *   copyright            : (C) 2002 Meik Sievertsen
   *   email                : acyd.burn@gmx.de
   *
!  *   $Id: posting_attachments.php,v 1.51 2003/01/17 09:29:45 acydburn Exp $
   *
   *
   ***************************************************************************/
--- 6,12 ----
   *   copyright            : (C) 2002 Meik Sievertsen
   *   email                : acyd.burn@gmx.de
   *
!  *   $Id: posting_attachments.php,v 1.54 2003/01/29 11:43:57 acydburn Exp $
   *
   *
   ***************************************************************************/
***************
*** 81,89 ****
  	//
  	// Get Quota Limits
  	//
! 	function get_quota_limits($user_id = -1)
  	{
! 		global $userdata, $attach_config, $db;
  
  		//
  		// Define Filesize Limits (Prepare Quota Settings)
--- 81,89 ----
  	//
  	// Get Quota Limits
  	//
! 	function get_quota_limits($userdata_quota, $user_id = -1)
  	{
! 		global $attach_config, $db;
  
  		//
  		// Define Filesize Limits (Prepare Quota Settings)
***************
*** 98,104 ****
  		// Change this to 'user;group' if you want to have first priority on user quota settings.
  		$priority = 'group;user';
  		
! 		if ( $userdata['user_level'] == ADMIN )
  		{
  			$attach_config['pm_filesize_limit'] = 0; // Unlimited
  			$attach_config['upload_filesize_limit'] = 0; // Unlimited
--- 98,104 ----
  		// Change this to 'user;group' if you want to have first priority on user quota settings.
  		$priority = 'group;user';
  		
! 		if ( $userdata_quota['user_level'] == ADMIN )
  		{
  			$attach_config['pm_filesize_limit'] = 0; // Unlimited
  			$attach_config['upload_filesize_limit'] = 0; // Unlimited
***************
*** 120,126 ****
  
  		if ($user_id == -1)
  		{
! 			$user_id = $userdata['user_id'];
  		}
  		
  		$priority = explode(';', $priority);
--- 120,126 ----
  
  		if ($user_id == -1)
  		{
! 			$user_id = intval($userdata_quota['user_id']);
  		}
  		
  		$priority = explode(';', $priority);
***************
*** 1150,1156 ****
  
  			}
  
! 			$this->get_quota_limits();
  
  			//
  			// Check our user quota
--- 1150,1156 ----
  
  			}
  
! 			$this->get_quota_limits($userdata);
  
  			//
  			// Check our user quota
***************
*** 1249,1255 ****
  				//
  				// Check Receivers PM Quota
  				//
! 				if (!empty($to_user))
  				{
  					$sql = "SELECT user_id
  					FROM " . USERS_TABLE . "
--- 1249,1255 ----
  				//
  				// Check Receivers PM Quota
  				//
! 				if ((!empty($to_user)) && ($userdata['user_level'] != ADMIN))
  				{
  					$sql = "SELECT user_id
  					FROM " . USERS_TABLE . "
***************
*** 1263,1269 ****
  					$row = $db->sql_fetchrow($result);
  					$user_id = intval($row['user_id']);
  					
! 					$this->get_quota_limits($user_id);
  
  					if (intval($attach_config['pm_filesize_limit']) != 0)
  					{
--- 1263,1270 ----
  					$row = $db->sql_fetchrow($result);
  					$user_id = intval($row['user_id']);
  					
! 					$u_data = get_userdata($user_id);
! 					$this->get_quota_limits($u_data, $user_id);
  
  					if (intval($attach_config['pm_filesize_limit']) != 0)
  					{
diff -c -rNbB attach_mod_235/download.php attach_mod_236/download.php
*** attach_mod_235/download.php	Mon Feb  3 15:37:27 2003
--- attach_mod_236/download.php	Mon Feb  3 15:37:22 2003
***************
*** 6,12 ****
   *   copyright            : (C) 2002 Meik Sievertsen
   *   email                : acyd.burn@gmx.de
   *
!  *   $Id: download.php,v 1.27 2003/01/15 23:24:27 acydburn Exp $
   *
   *
   ***************************************************************************/
--- 6,12 ----
   *   copyright            : (C) 2002 Meik Sievertsen
   *   email                : acyd.burn@gmx.de
   *
!  *   $Id: download.php,v 1.30 2003/02/02 18:34:45 acydburn Exp $
   *
   *
   ***************************************************************************/
***************
*** 54,60 ****
  //
  function send_file_to_browser($real_filename, $mimetype, $physical_filename, $upload_dir, $attach_id)
  {
! 	global $_SERVER, $HTTP_USER_AGENT, $HTTP_SERVER_VARS, $lang, $db;
  
  	if ($upload_dir == '')
  	{
--- 54,60 ----
  //
  function send_file_to_browser($real_filename, $mimetype, $physical_filename, $upload_dir, $attach_id)
  {
! 	global $_SERVER, $HTTP_USER_AGENT, $HTTP_SERVER_VARS, $lang, $db, $attach_config;
  
  	if ($upload_dir == '')
  	{
***************
*** 160,165 ****
--- 160,166 ----
  		header('Content-Type: ' . $mimetype . '; name="' . $real_filename . '"');
  		header('Content-Disposition: attachment; filename=' . $real_filename);
  	}
+ 	header('Pragma: public');
  
  	//
  	// Now send the File Contents to the Browser
***************
*** 185,195 ****
  			$mode = FTP_ASCII;
  		}
  
! 		$result = @ftp_get($conn_id, $tmp_filename, $physical_filename, $mode);
  
  		if (!$result) 
  		{
! 			message_die(GENERAL_MESSAGE, 'FTP Download Error');
  		} 
  	
  		@ftp_quit($conn_id);
--- 186,196 ----
  			$mode = FTP_ASCII;
  		}
  
! 		$result = @ftp_get($conn_id, $tmp_filename, $filename, $mode);
  
  		if (!$result) 
  		{
! 			message_die(GENERAL_ERROR, $lang['Error_no_attachment'] . "<br /><br /><b>404 File Not Found:</b> The File <i>" . $filename . "</i> does not exist.");
  		} 
  	
  		@ftp_quit($conn_id);
***************
*** 366,372 ****
  
  	if (intval($attach_config['allow_ftp_upload']))
  	{
! 		$url = $attach_config['download_path'] . '/' . $attachment['physical_filename'];
  		$redirect_path = $url;
  	}
  	else
--- 367,378 ----
  
  	if (intval($attach_config['allow_ftp_upload']))
  	{
! 		if (trim($attach_config['download_path']) == '')
! 		{
! 			message_die(GENERAL_ERROR, 'Physical Download not possible with the current Attachment Setting');
! 		}
! 		
! 		$url = trim($attach_config['download_path']) . '/' . $attachment['physical_filename'];
  		$redirect_path = $url;
  	}
  	else
***************
*** 392,398 ****
  {
  	if (intval($attach_config['allow_ftp_upload']))
  	{
! 		send_file_to_browser($attachment['real_filename'], $attachment['mimetype'], $attach_config['download_path'] . '/' . $attachment['physical_filename'] , '', $attachment['attach_id']);
  		exit();
  	}
  	else
--- 398,405 ----
  {
  	if (intval($attach_config['allow_ftp_upload']))
  	{
! 		// We do not need a download path, we are not downloading physically
! 		send_file_to_browser($attachment['real_filename'], $attachment['mimetype'], $attachment['physical_filename'] , '', $attachment['attach_id']);
  		exit();
  	}
  	else
diff -c -rNbB attach_mod_235/files/.htaccess attach_mod_236/files/.htaccess
*** attach_mod_235/files/.htaccess	Mon Feb  3 15:37:27 2003
--- attach_mod_236/files/.htaccess	Mon Feb  3 15:37:22 2003
***************
*** 1 ****
! Options -Indexes
--- 1,2 ----
! 
! Options -Includes -ExecCGI -Indexes
diff -c -rNbB attach_mod_235/templates/subSilver/viewtopic_attach_body.tpl attach_mod_236/templates/subSilver/viewtopic_attach_body.tpl
*** attach_mod_235/templates/subSilver/viewtopic_attach_body.tpl	Mon Feb  3 15:37:27 2003
--- attach_mod_236/templates/subSilver/viewtopic_attach_body.tpl	Mon Feb  3 15:37:22 2003
***************
*** 2,7 ****
--- 2,8 ----
  <style type="text/css">
  <!--
  td.attachrow		{ font: normal 11px Verdana, Arial, Helvetica, sans-serif; color : {T_BODY_TEXT}; border-color : {T_BODY_TEXT}; }
+ td.attachheader     { font: normal 11px Verdana, Arial, Helvetica, sans-serif; color : {T_BODY_TEXT}; border-color : {T_BODY_TEXT}; background-color: {T_TR_COLOR3}; }
  table.attachtable	{ font: normal 12px Verdana, Arial, Helvetica, sans-serif; color : {T_BODY_TEXT}; border-color : {T_BODY_TEXT};	border-collapse : collapse; }
  -->
  </style>
***************
*** 10,28 ****
  	<br /><br />
            
  	<!-- BEGIN denyrow -->
! 	<center><hr width="95%"></hr></center>
  	<table width="95%" border="1" cellpadding="2" cellspacing="0" class="attachtable" align="center">
  	<tr>
! 		<td width="100%" class="spaceRow" align="center"><b><span class="gen">{postrow.attach.denyrow.L_DENIED}</span></b></td>
  	</tr>
  	</table>
! 	<center><hr width="95%"></hr></center>
  	<!-- END denyrow -->
  	<!-- BEGIN cat_stream -->
! 	<center><hr width="95%"></hr></center>
  	<table width="95%" border="1" cellpadding="2" cellspacing="0" class="attachtable" align="center">
  	<tr>
! 		<td width="100%" colspan="3" class="spaceRow" align="center"><b><span class="gen">{postrow.attach.cat_stream.DOWNLOAD_NAME}</span></b></td>
  	</tr>
  	<tr>
  		<td width="15%" class="attachrow"><span class="genmed">&nbsp;{L_DESCRIPTION}:</span></td>
--- 11,29 ----
  	<br /><br />
            
  	<!-- BEGIN denyrow -->
! 	<div align="center"><hr width="95%" /></div>
  	<table width="95%" border="1" cellpadding="2" cellspacing="0" class="attachtable" align="center">
  	<tr>
! 		<td width="100%" class="attachheader" align="center"><b><span class="gen">{postrow.attach.denyrow.L_DENIED}</span></b></td>
  	</tr>
  	</table>
! 	<div align="center"><hr width="95%" /></div>
  	<!-- END denyrow -->
  	<!-- BEGIN cat_stream -->
! 	<div align="center"><hr width="95%" /></div>
  	<table width="95%" border="1" cellpadding="2" cellspacing="0" class="attachtable" align="center">
  	<tr>
! 		<td width="100%" colspan="2" class="attachheader" align="center"><b><span class="gen">{postrow.attach.cat_stream.DOWNLOAD_NAME}</span></b></td>
  	</tr>
  	<tr>
  		<td width="15%" class="attachrow"><span class="genmed">&nbsp;{L_DESCRIPTION}:</span></td>
***************
*** 59,71 ****
  		</td>
  	</tr>
  	</table>
! 	<center><hr width="95%"></hr></center>
  	<!-- END cat_stream -->
  	<!-- BEGIN cat_swf -->
! 	<center><hr width="95%"></hr></center>
  	<table width="95%" border="1" cellpadding="2" cellspacing="0" class="attachtable" align="center">
  	<tr>
! 		<td width="100%" colspan="3" class="spaceRow" align="center"><b><span class="gen">{postrow.attach.cat_swf.DOWNLOAD_NAME}</span></b></td>
  	</tr>
  	<tr>
  		<td width="15%" class="attachrow"><span class="genmed">&nbsp;{L_DESCRIPTION}:</span></td>
--- 60,72 ----
  		</td>
  	</tr>
  	</table>
! 	<div align="center"><hr width="95%" /></div>
  	<!-- END cat_stream -->
  	<!-- BEGIN cat_swf -->
! 	<div align="center"><hr width="95%" /></div>
  	<table width="95%" border="1" cellpadding="2" cellspacing="0" class="attachtable" align="center">
  	<tr>
! 		<td width="100%" colspan="2" class="attachheader" align="center"><b><span class="gen">{postrow.attach.cat_swf.DOWNLOAD_NAME}</span></b></td>
  	</tr>
  	<tr>
  		<td width="15%" class="attachrow"><span class="genmed">&nbsp;{L_DESCRIPTION}:</span></td>
***************
*** 99,111 ****
  		</td>
  	</tr>
  	</table>
! 	<center><hr width="95%"></hr></center>
  	<!-- END cat_swf -->
  	<!-- BEGIN cat_images -->
! 	<center><hr width="95%"></hr></center>
  	<table width="95%" border="1" cellpadding="2" cellspacing="0" class="attachtable" align="center">
  	<tr>
! 		<td width="100%" colspan="3" class="spaceRow" align="center"><b><span class="gen">{postrow.attach.cat_images.DOWNLOAD_NAME}</span></b></td>
  	</tr>
  	<tr>
  		<td width="15%" class="attachrow"><span class="genmed">&nbsp;{L_DESCRIPTION}:</span></td>
--- 100,112 ----
  		</td>
  	</tr>
  	</table>
! 	<div align="center"><hr width="95%" /></div>
  	<!-- END cat_swf -->
  	<!-- BEGIN cat_images -->
! 	<div align="center"><hr width="95%" /></div>
  	<table width="95%" border="1" cellpadding="2" cellspacing="0" class="attachtable" align="center">
  	<tr>
! 		<td width="100%" colspan="2" class="attachheader" align="center"><b><span class="gen">{postrow.attach.cat_images.DOWNLOAD_NAME}</span></b></td>
  	</tr>
  	<tr>
  		<td width="15%" class="attachrow"><span class="genmed">&nbsp;{L_DESCRIPTION}:</span></td>
***************
*** 129,141 ****
  		<td colspan="2" align="center"><br /><img src="{postrow.attach.cat_images.IMG_SRC}" alt="{postrow.attach.cat_images.DOWNLOAD_NAME}" border="0" /><br /><br /></td>
  	</tr>
  	</table>
! 	<center><hr width="95%"></hr></center>
  	<!-- END cat_images -->
  	<!-- BEGIN cat_thumb_images -->
! 	<center><hr width="95%"></hr></center>
  	<table width="95%" border="1" cellpadding="2" cellspacing="0" class="attachtable" align="center">
  	<tr>
! 		<td width="100%" colspan="3" class="spaceRow" align="center"><b><span class="gen">{postrow.attach.cat_thumb_images.DOWNLOAD_NAME}</span></b></td>
  	</tr>
  	<tr>
  		<td width="15%" class="attachrow"><span class="genmed">&nbsp;{L_DESCRIPTION}:</span></td>
--- 130,142 ----
  		<td colspan="2" align="center"><br /><img src="{postrow.attach.cat_images.IMG_SRC}" alt="{postrow.attach.cat_images.DOWNLOAD_NAME}" border="0" /><br /><br /></td>
  	</tr>
  	</table>
! 	<div align="center"><hr width="95%" /></div>
  	<!-- END cat_images -->
  	<!-- BEGIN cat_thumb_images -->
! 	<div align="center"><hr width="95%" /></div>
  	<table width="95%" border="1" cellpadding="2" cellspacing="0" class="attachtable" align="center">
  	<tr>
! 		<td width="100%" colspan="2" class="attachheader" align="center"><b><span class="gen">{postrow.attach.cat_thumb_images.DOWNLOAD_NAME}</span></b></td>
  	</tr>
  	<tr>
  		<td width="15%" class="attachrow"><span class="genmed">&nbsp;{L_DESCRIPTION}:</span></td>
***************
*** 159,171 ****
  		<td colspan="2" align="center"><br /><a href="{postrow.attach.cat_thumb_images.IMG_SRC}" target="_blank"><img src="{postrow.attach.cat_thumb_images.IMG_THUMB_SRC}" alt="{postrow.attach.cat_thumb_images.DOWNLOAD_NAME}" border="0" /></a><br /><br /></td>
  	</tr>
  	</table>
! 	<center><hr width="95%"></hr></center>
  	<!-- END cat_thumb_images -->
  	<!-- BEGIN attachrow -->
! 	<center><hr width="95%"></hr></center>
  	<table width="95%" border="1" cellpadding="2" cellspacing="0" class="attachtable" align="center">
  	<tr>
! 		<td width="100%" colspan="3" class="spaceRow" align="center"><b><span class="gen">{postrow.attach.attachrow.DOWNLOAD_NAME}</span></b></td>
  	</tr>
  	<tr>
  		<td width="15%" class="attachrow"><span class="genmed">&nbsp;{L_DESCRIPTION}:</span></td>
--- 160,172 ----
  		<td colspan="2" align="center"><br /><a href="{postrow.attach.cat_thumb_images.IMG_SRC}" target="_blank"><img src="{postrow.attach.cat_thumb_images.IMG_THUMB_SRC}" alt="{postrow.attach.cat_thumb_images.DOWNLOAD_NAME}" border="0" /></a><br /><br /></td>
  	</tr>
  	</table>
! 	<div align="center"><hr width="95%" /></div>
  	<!-- END cat_thumb_images -->
  	<!-- BEGIN attachrow -->
! 	<div align="center"><hr width="95%" /></div>
  	<table width="95%" border="1" cellpadding="2" cellspacing="0" class="attachtable" align="center">
  	<tr>
! 		<td width="100%" colspan="3" class="attachheader" align="center"><b><span class="gen">{postrow.attach.attachrow.DOWNLOAD_NAME}</span></b></td>
  	</tr>
  	<tr>
  		<td width="15%" class="attachrow"><span class="genmed">&nbsp;{L_DESCRIPTION}:</span></td>
***************
*** 191,197 ****
  		<td width="75%" class="attachrow"><span class="genmed">&nbsp;{postrow.attach.attachrow.L_DOWNLOAD_COUNT}</span></td>
  	</tr>
  	</table>
! 	<center><hr width="95%"></hr></center>
  	<!-- END attachrow -->
  	
  <!-- END attach -->
--- 192,198 ----
  		<td width="75%" class="attachrow"><span class="genmed">&nbsp;{postrow.attach.attachrow.L_DOWNLOAD_COUNT}</span></td>
  	</tr>
  	</table>
! 	<div align="center"><hr width="95%" /></div>
  	<!-- END attachrow -->
  	
  <!-- END attach -->
diff -c -rNbB attach_mod_235/uacp.php attach_mod_236/uacp.php
*** attach_mod_235/uacp.php	Mon Feb  3 15:37:27 2003
--- attach_mod_236/uacp.php	Mon Feb  3 15:37:22 2003
***************
*** 6,12 ****
   *   copyright            : (C) 2002 Meik Sievertsen
   *   email                : acyd.burn@gmx.de
   *
!  *   $Id: uacp.php,v 1.6 2003/01/13 18:19:48 acydburn Exp $
   *
   *
   ***************************************************************************/
--- 6,12 ----
   *   copyright            : (C) 2002 Meik Sievertsen
   *   email                : acyd.burn@gmx.de
   *
!  *   $Id: uacp.php,v 1.10 2003/02/03 12:33:51 acydburn Exp $
   *
   *
   ***************************************************************************/
***************
*** 31,36 ****
--- 31,46 ----
  include($phpbb_root_path . 'extension.inc');
  include($phpbb_root_path . 'common.'.$phpEx);
  
+ // session id check
+ if (!empty($HTTP_POST_VARS['sid']) || !empty($HTTP_GET_VARS['sid']))
+ {
+ 	$sid = (!empty($HTTP_POST_VARS['sid'])) ? $HTTP_POST_VARS['sid'] : $HTTP_GET_VARS['sid'];
+ }
+ else
+ {
+ 	$sid = '';
+ }
+ 
  //
  // Start session management
  //
***************
*** 40,45 ****
--- 50,61 ----
  // End session management
  //
  
+ // session id check
+ if ($sid == '' || $sid != $userdata['session_id'])
+ {
+ 	message_die(GENERAL_ERROR, 'Invalid_session');
+ }
+ 
  //
  // Obtain initial var settings
  //
***************
*** 74,82 ****
  $page_title = $lang['User_acp_title'];
  include($phpbb_root_path . 'includes/page_header.'.$phpEx);
  
  if( !@file_exists(@amod_realpath($phpbb_root_path . 'language/lang_' . $language . '/lang_admin_attach.'.$phpEx)) )
  {
! 	$language = 'english';
  }
  
  include($phpbb_root_path . 'language/lang_' . $language . '/lang_admin_attach.' . $phpEx);
--- 90,100 ----
  $page_title = $lang['User_acp_title'];
  include($phpbb_root_path . 'includes/page_header.'.$phpEx);
  
+ $language = $board_config['default_lang'];
+ 
  if( !@file_exists(@amod_realpath($phpbb_root_path . 'language/lang_' . $language . '/lang_admin_attach.'.$phpEx)) )
  {
! 	$language = $attach_config['board_lang'];
  }
  
  include($phpbb_root_path . 'language/lang_' . $language . '/lang_admin_attach.' . $phpEx);
***************
*** 201,206 ****
--- 219,225 ----
  	$hidden_fields .= '<input type="hidden" name="order" value="' . $sort_order . '" />';
  	$hidden_fields .= '<input type="hidden" name="' . POST_USERS_URL . '" value="' . $profiledata['user_id'] . '" />';
  	$hidden_fields .= '<input type="hidden" name="start" value="' . $start . '" />';
+ 	$hidden_fields .= '<input type="hidden" name="sid" value="' . $userdata['session_id'] . '" />';
  
  	for($i = 0; $i < count($delete_id_list); $i++)
  	{
***************
*** 240,245 ****
--- 259,265 ----
  $username = $profiledata['username'];
  
  $s_hidden = '<input type="hidden" name="' . POST_USERS_URL . '" value="' . $profiledata['user_id'] . '">';
+ $s_hidden .= '<input type="hidden" name="sid" value="' . $userdata['session_id'] . '" />';
  
  //
  // Assign Template Vars
***************
*** 281,313 ****
  		
  $attach_ids = $db->sql_fetchrowset($result);
  $num_attach_ids = $db->sql_numrows($result);
- 
- if ($num_attach_ids == 0)
- {
- 	message_die(GENERAL_MESSAGE, 'For some reason no Attachments are assigned to the User "' . $username . '".');
- }
- 		
  $total_rows = $num_attach_ids;
  
! $attach_id = array();
! 
! for ($j = 0; $j < $num_attach_ids; $j++)
  {
  	$attach_id[] = $attach_ids[$j]['attach_id'];
! }
  			
! $sql = "SELECT a.*
! FROM " . ATTACHMENTS_DESC_TABLE . " a
! WHERE a.attach_id IN (" . implode(', ', $attach_id) . ") " .
! $order_by;
  		
! if ( !($result = attach_sql_query($sql)) )
! {
  	message_die(GENERAL_ERROR, 'Couldn\'t query attachments', '', __LINE__, __FILE__, $sql);
! }
  
! $attachments = $db->sql_fetchrowset($result);
! $num_attach = $db->sql_numrows($result);
  
  if (count($attachments) > 0)
  {
--- 301,334 ----
  		
  $attach_ids = $db->sql_fetchrowset($result);
  $num_attach_ids = $db->sql_numrows($result);
  $total_rows = $num_attach_ids;
  
! if ($num_attach_ids > 0)
  {
+ 	$attach_id = array();
+ 
+ 	for ($j = 0; $j < $num_attach_ids; $j++)
+ 	{
  		$attach_id[] = $attach_ids[$j]['attach_id'];
! 	}
  			
! 	$sql = "SELECT a.*
! 	FROM " . ATTACHMENTS_DESC_TABLE . " a
! 	WHERE a.attach_id IN (" . implode(', ', $attach_id) . ") " .
! 	$order_by;
  		
! 	if ( !($result = attach_sql_query($sql)) )
! 	{
  		message_die(GENERAL_ERROR, 'Couldn\'t query attachments', '', __LINE__, __FILE__, $sql);
! 	}
  
! 	$attachments = $db->sql_fetchrowset($result);
! 	$num_attach = $db->sql_numrows($result);
! }
! else
! {
! 	$attachments = array();
! }
  
  if (count($attachments) > 0)
  {
***************
*** 373,385 ****
  			}
  			else
  			{
! 				$post_titles[] = $lang['Private_Message'];
  			}
  		}
  
  		$post_titles = implode('<br />', $post_titles);
  
  		$hidden_field = '<input type="hidden" name="attach_id_list[]" value="' . $attachments[$i]['attach_id'] . '">';
  
  		$template->assign_block_vars('attachrow', array(
  			'ROW_NUMBER' => $i + ( $HTTP_GET_VARS['start'] + 1 ),
--- 394,433 ----
  			}
  			else
  			{
! 				$desc = $lang['Private_Message'];
! 				$sql = "SELECT privmsgs_type
! 				FROM " . PRIVMSGS_TABLE . "
! 				WHERE privmsgs_id = " . $ids[$j]['privmsgs_id'];
! 
! 				if ( !($result = attach_sql_query($sql)) )
! 				{
! 					message_die(GENERAL_ERROR, 'Couldn\'t get Privmsgs Type', '', __LINE__, __FILE__, $sql);
! 				}
! 		
! 				$row = $db->sql_fetchrow($result);
! 				$privmsgs_type = $row['privmsgs_type'];
! 								
! 				if (($privmsgs_type == PRIVMSGS_READ_MAIL) || ($privmsgs_type == PRIVMSGS_NEW_MAIL) || ($privmsgs_type == PRIVMSGS_UNREAD_MAIL))
! 				{
! 					$desc .= ' (' . $lang['Inbox'] . ')';
! 				}
! 				else if ($privmsgs_type == PRIVMSGS_SENT_MAIL)
! 				{
! 					$desc .= ' (' . $lang['Sentbox'] . ')';
! 				}
! 				else if ( ($privmsgs_type == PRIVMSGS_SAVED_IN_MAIL) || ($privmsgs_type == PRIVMSGS_SAVED_OUT_MAIL) )
! 				{
! 					$desc .= ' (' . $lang['Savebox'] . ')';
! 				}
! 
! 				$post_titles[] = $desc;
  			}
  		}
  
  		$post_titles = implode('<br />', $post_titles);
  
  		$hidden_field = '<input type="hidden" name="attach_id_list[]" value="' . $attachments[$i]['attach_id'] . '">';
+ 		$hidden_field .= '<input type="hidden" name="sid" value="' . $userdata['session_id'] . '" />';
  
  		$template->assign_block_vars('attachrow', array(
  			'ROW_NUMBER' => $i + ( $HTTP_GET_VARS['start'] + 1 ),
***************
*** 408,414 ****
  //
  if ( ($do_pagination) && ($total_rows > $board_config['topics_per_page']) )
  {
! 	$pagination = generate_pagination($phpbb_root_path . 'uacp.' . $phpEx . '?mode=' . $mode . '&amp;order=' . $sort_order . '&amp;' . POST_USERS_URL . '=' . $profiledata['user_id'], $total_rows, $board_config['topics_per_page'], $start).'&nbsp;';
  
  	$template->assign_vars(array(
  		'PAGINATION' => $pagination,
--- 456,462 ----
  //
  if ( ($do_pagination) && ($total_rows > $board_config['topics_per_page']) )
  {
! 	$pagination = generate_pagination($phpbb_root_path . 'uacp.' . $phpEx . '?mode=' . $mode . '&amp;order=' . $sort_order . '&amp;' . POST_USERS_URL . '=' . $profiledata['user_id'] . '&amp;sid=' . $userdata['session_id'], $total_rows, $board_config['topics_per_page'], $start).'&nbsp;';
  
  	$template->assign_vars(array(
  		'PAGINATION' => $pagination,
