diff --git a/viewimage.php b/viewimage.php
index 116ae34..115c7c3 100644
--- a/viewimage.php
+++ b/viewimage.php
@@ -31,15 +31,28 @@
loggedinorreturn();
-$pic = htmlspecialchars_uni((string) $_GET["pic"]);
+$pic = html_uni($_GET["pic"]);
-stdhead("Οπξρμξςπ κΰπςθνκθ");
-print("
$pic
\n");
-print("
\n");
-?>
+if(empty($pic))
+stderr("ΠΠ½ΠΈΠΌΠ°Π½ΠΈΠ΅, ΠΎΠ±Π½Π°ΡΡΠΆΠ΅Π½Π° ΠΎΡΠΈΠ±ΠΊΠ°", "ΠΠΎ Π΄Π°Π½Π½ΠΎΠΌΡ Π°Π΄ΡΠ΅ΡΡ ΠΏΡΠ±Π»ΠΈΠΊΠ°ΡΠΈΠΉ Π½Π° ΡΠ°ΠΉΡΠ΅ Π½Π΅ Π½Π°ΠΉΠ΄Π΅Π½ΠΎ, Π»ΠΈΠ±ΠΎ Ρ Π²Π°Ρ Π½Π΅Ρ Π΄ΠΎΡΡΡΠΏΠ° Π΄Π»Ρ ΠΏΡΠΎΡΠΌΠΎΡΡΠ° ΠΈΠ½ΡΠΎΡΠΌΠ°ΡΠΈΠΈ ΠΏΠΎ Π΄Π°Π½Π½ΠΎΠΌΡ Π°Π΄ΡΠ΅ΡΡ.");
-
+$allowed_image_types = array("image/gif" => "gif", "image/png" => "png", "image/jpeg" => "jpeg", "image/jpg" => "jpg");
-
+$file_extension = pathinfo($pic, PATHINFO_EXTENSION);
+
+if (!in_array($file_extension, $allowed_image_types))
+stderr("ΠΠ½ΠΈΠΌΠ°Π½ΠΈΠ΅, ΠΎΠ±Π½Π°ΡΡΠΆΠ΅Π½Π° ΠΎΡΠΈΠ±ΠΊΠ°", "ΠΠΎ Π΄Π°Π½Π½ΠΎΠΌΡ Π°Π΄ΡΠ΅ΡΡ ΠΏΡΠ±Π»ΠΈΠΊΠ°ΡΠΈΠΉ Π½Π° ΡΠ°ΠΉΡΠ΅ Π½Π΅ Π½Π°ΠΉΠ΄Π΅Π½ΠΎ, Π»ΠΈΠ±ΠΎ Ρ Π²Π°Ρ Π½Π΅Ρ Π΄ΠΎΡΡΡΠΏΠ° Π΄Π»Ρ ΠΏΡΠΎΡΠΌΠΎΡΡΠ° ΠΈΠ½ΡΠΎΡΠΌΠ°ΡΠΈΠΈ ΠΏΠΎ Π΄Π°Π½Π½ΠΎΠΌΡ Π°Π΄ΡΠ΅ΡΡ.");
+
+
+stdhead("ΠΡΠΎΡΠΌΠΎΡΡ ΠΊΠ°ΡΡΠΈΠ½ΠΊΠΈ");
+
+
+
+print("".$pic."
\n");
+
+
+print(")
\n");
+echo "";
stdfoot();
-?>
\ No newline at end of file
+?>