$tmpdir .= '/' . sprintf('%08x%08x', mt_rand(), mt_rand());
mkdir($tmpdir);
- $dirname = preg_replace('|[^a-z0-9_-]|', '', $dirname);
+ $dirname = preg_replace('|[^a-z0-9_-]|i', '', $dirname);
if($dirname == '') $dirname = 'foo';
mkdir("$tmpdir/$dirname");
foreach($files as $filename => $file_data) {