Fix JavaScript alert string escaping
This commit is contained in:
@@ -123,7 +123,7 @@ if ($w == "" || $w == "u")
|
||||
$sql = " select mb_id from {$g5['member_table']} where mb_id = '$ca_mb_id' ";
|
||||
$row = sql_fetch($sql);
|
||||
if (!$row['mb_id'])
|
||||
alert("\'$ca_mb_id\' 은(는) 존재하는 회원아이디가 아닙니다.");
|
||||
alert("'$ca_mb_id' 은(는) 존재하는 회원아이디가 아닙니다.");
|
||||
}
|
||||
}
|
||||
|
||||
@@ -256,4 +256,4 @@ if ($w == "" || $w == "u")
|
||||
goto_url("./categoryform.php?w=u&ca_id=$ca_id&$qstr");
|
||||
} else {
|
||||
goto_url("./categorylist.php?$qstr");
|
||||
}
|
||||
}
|
||||
|
||||
@@ -19,7 +19,7 @@ for ($i=0; $i<$post_ca_id_count; $i++)
|
||||
$sql = " select mb_id from {$g5['member_table']} where mb_id = '".sql_real_escape_string($str_ca_mb_id)."' ";
|
||||
$row = sql_fetch($sql);
|
||||
if (!$row['mb_id'])
|
||||
alert("\'{$str_ca_mb_id}\' 은(는) 존재하는 회원아이디가 아닙니다.", "./categorylist.php?$qstr");
|
||||
alert("'{$str_ca_mb_id}' 은(는) 존재하는 회원아이디가 아닙니다.", "./categorylist.php?$qstr");
|
||||
}
|
||||
|
||||
$check_files = array();
|
||||
@@ -94,4 +94,4 @@ for ($i=0; $i<$post_ca_id_count; $i++)
|
||||
|
||||
}
|
||||
|
||||
goto_url("./categorylist.php?$qstr");
|
||||
goto_url("./categorylist.php?$qstr");
|
||||
|
||||
@@ -384,10 +384,16 @@ sql_query($sql);
|
||||
$sql = " delete from {$g5['g5_shop_order_data_table']} where od_id = '$od_id' and dt_pg = '$od_pg' ";
|
||||
sql_query($sql, true);
|
||||
|
||||
$orderform_url = './orderform.php?od_id='.$od_id;
|
||||
$inorderlist_url = './inorderlist.php?'.str_replace('&', '&', $qstr);
|
||||
$js_replace = array('\\' => '\\\\', '"' => '\\"', "'" => '\\u0027', '/' => '\\/', "\r" => '\\r', "\n" => '\\n', "\t" => '\\t', '<' => '\\u003C', '>' => '\\u003E', '&' => '\\u0026', "\xE2\x80\xA8" => '\\u2028', "\xE2\x80\xA9" => '\\u2029');
|
||||
$js_orderform_url = function_exists('get_js_safe_string') ? get_js_safe_string($orderform_url) : '"'.strtr((string)$orderform_url, $js_replace).'"';
|
||||
$js_inorderlist_url = function_exists('get_js_safe_string') ? get_js_safe_string($inorderlist_url) : '"'.strtr((string)$inorderlist_url, $js_replace).'"';
|
||||
|
||||
echo '<meta http-equiv="content-type" content="text/html; charset=utf-8">'.PHP_EOL;
|
||||
echo '<script>'.PHP_EOL;
|
||||
echo 'if(confirm("복구하신 주문 상세페이지로 이동하시겠습니까?"))'.PHP_EOL;
|
||||
echo 'document.location.href = "./orderform.php?od_id='.$od_id.'";'.PHP_EOL;
|
||||
echo 'document.location.href = '.$js_orderform_url.';'.PHP_EOL;
|
||||
echo 'else'.PHP_EOL;
|
||||
echo 'document.location.href = "./inorderlist.php?'.str_replace('&', '&', $qstr).'";'.PHP_EOL;
|
||||
echo '</script>'.PHP_EOL;
|
||||
echo 'document.location.href = '.$js_inorderlist_url.';'.PHP_EOL;
|
||||
echo '</script>'.PHP_EOL;
|
||||
|
||||
@@ -105,7 +105,7 @@ else if ($w == "u")
|
||||
and b.ca_mb_id = '{$member['mb_id']}' ";
|
||||
$row = sql_fetch($sql);
|
||||
if (!$row['it_id'])
|
||||
alert("\'{$member['mb_id']}\' 님께서 수정 할 권한이 없는 상품입니다.");
|
||||
alert("'{$member['mb_id']}' 님께서 수정 할 권한이 없는 상품입니다.");
|
||||
}
|
||||
|
||||
$it = get_shop_item($it_id);
|
||||
@@ -1901,4 +1901,4 @@ categorychange(document.fitemform);
|
||||
</script>
|
||||
|
||||
<?php
|
||||
include_once (G5_ADMIN_PATH.'/admin.tail.php');
|
||||
include_once (G5_ADMIN_PATH.'/admin.tail.php');
|
||||
|
||||
@@ -513,7 +513,7 @@ else if ($w == "d")
|
||||
and b.ca_mb_id = '{$member['mb_id']}' ";
|
||||
$row = sql_fetch($sql);
|
||||
if (!$row['it_id'])
|
||||
alert("\'{$member['mb_id']}\' 님께서 삭제 할 권한이 없는 상품입니다.");
|
||||
alert("'{$member['mb_id']}' 님께서 삭제 할 권한이 없는 상품입니다.");
|
||||
}
|
||||
|
||||
itemdelete($it_id);
|
||||
|
||||
+7
-3
@@ -40,6 +40,10 @@ $url = preg_replace('/\r\n|\r|\n|[^\x20-\x7e]/','', $url);
|
||||
|
||||
// url 체크
|
||||
check_url_host($url, $msg);
|
||||
$alert_url = str_replace('&', '&', $url);
|
||||
$js_replace = array('\\' => '\\\\', '"' => '\\"', "'" => '\\u0027', '/' => '\\/', "\r" => '\\r', "\n" => '\\n', "\t" => '\\t', '<' => '\\u003C', '>' => '\\u003E', '&' => '\\u0026', "\xE2\x80\xA8" => '\\u2028', "\xE2\x80\xA9" => '\\u2029');
|
||||
$js_alert_msg = function_exists('get_js_safe_string') ? get_js_safe_string($alert_msg) : '"'.strtr((string)$alert_msg, $js_replace).'"';
|
||||
$js_alert_url = function_exists('get_js_safe_string') ? get_js_safe_string($alert_url) : '"'.strtr((string)$alert_url, $js_replace).'"';
|
||||
|
||||
if($error) {
|
||||
$header2 = "다음 항목에 오류가 있습니다.";
|
||||
@@ -49,9 +53,9 @@ if($error) {
|
||||
?>
|
||||
|
||||
<script>
|
||||
alert(<?php echo function_exists('get_js_safe_string') ? get_js_safe_string($alert_msg) : '""'; ?>);
|
||||
alert(<?php echo $js_alert_msg; ?>);
|
||||
<?php if ($url) { ?>
|
||||
document.location.replace("<?php echo str_replace('&', '&', $url); ?>");
|
||||
document.location.replace(<?php echo $js_alert_url; ?>);
|
||||
<?php } else { ?>
|
||||
history.back();
|
||||
<?php } ?>
|
||||
@@ -114,4 +118,4 @@ history.back();
|
||||
</noscript>
|
||||
|
||||
<?php
|
||||
include_once(G5_PATH.'/tail.sub.php');
|
||||
include_once(G5_PATH.'/tail.sub.php');
|
||||
|
||||
+3
-1
@@ -6,6 +6,8 @@ $msg = isset($msg) ? strip_tags($msg) : '';
|
||||
|
||||
$msg2 = str_replace(array("\\r\\n", "\\n", "\\r"), "<br>", $msg);
|
||||
$alert_msg = str_replace(array("\\r\\n", "\\n", "\\r"), "\n", $msg);
|
||||
$js_replace = array('\\' => '\\\\', '"' => '\\"', "'" => '\\u0027', '/' => '\\/', "\r" => '\\r', "\n" => '\\n', "\t" => '\\t', '<' => '\\u003C', '>' => '\\u003E', '&' => '\\u0026', "\xE2\x80\xA8" => '\\u2028', "\xE2\x80\xA9" => '\\u2029');
|
||||
$js_alert_msg = function_exists('get_js_safe_string') ? get_js_safe_string($alert_msg) : '"'.strtr((string)$alert_msg, $js_replace).'"';
|
||||
|
||||
if($error) {
|
||||
$header2 = "다음 항목에 오류가 있습니다.";
|
||||
@@ -17,7 +19,7 @@ if($error) {
|
||||
?>
|
||||
|
||||
<script>
|
||||
alert(<?php echo function_exists('get_js_safe_string') ? get_js_safe_string($alert_msg) : '""'; ?>);
|
||||
alert(<?php echo $js_alert_msg; ?>);
|
||||
try {
|
||||
window.close();
|
||||
} catch(error) {
|
||||
|
||||
@@ -7,7 +7,7 @@ $count = (isset($_POST['chk_wr_id']) && is_array($_POST['chk_wr_id'])) ? count($
|
||||
$post_btn_submit = isset($_POST['btn_submit']) ? clean_xss_tags($_POST['btn_submit'], 1, 1) : '';
|
||||
|
||||
if(!$count) {
|
||||
alert(addcslashes($post_btn_submit, '"\\/').' 하실 항목을 하나 이상 선택하세요.');
|
||||
alert($post_btn_submit.' 하실 항목을 하나 이상 선택하세요.');
|
||||
}
|
||||
|
||||
if($post_btn_submit === '선택삭제') {
|
||||
@@ -20,4 +20,4 @@ if($post_btn_submit === '선택삭제') {
|
||||
include './move.php';
|
||||
} else {
|
||||
alert('올바른 방법으로 이용해 주세요.');
|
||||
}
|
||||
}
|
||||
|
||||
+10
-4
@@ -14,6 +14,12 @@ $url3 = preg_replace($pattern2, "", $url3);
|
||||
|
||||
$msg = isset($msg) ? $msg : '';
|
||||
$header = isset($header) ? $msg : '';
|
||||
$confirm_msg = str_replace(array('<br>', '<br/>', '<br />'), "\n", $msg);
|
||||
$confirm_msg = strip_tags($confirm_msg);
|
||||
$js_replace = array('\\' => '\\\\', '"' => '\\"', "'" => '\\u0027', '/' => '\\/', "\r" => '\\r', "\n" => '\\n', "\t" => '\\t', '<' => '\\u003C', '>' => '\\u003E', '&' => '\\u0026', "\xE2\x80\xA8" => '\\u2028', "\xE2\x80\xA9" => '\\u2029');
|
||||
$js_confirm_msg = function_exists('get_js_safe_string') ? get_js_safe_string($confirm_msg) : '"'.strtr((string)$confirm_msg, $js_replace).'"';
|
||||
$js_url1 = function_exists('get_js_safe_string') ? get_js_safe_string($url1) : '"'.strtr((string)$url1, $js_replace).'"';
|
||||
$js_url2 = function_exists('get_js_safe_string') ? get_js_safe_string($url2) : '"'.strtr((string)$url2, $js_replace).'"';
|
||||
|
||||
// url 체크
|
||||
check_url_host($url1);
|
||||
@@ -22,11 +28,11 @@ check_url_host($url3);
|
||||
?>
|
||||
|
||||
<script>
|
||||
var conf = "<?php echo strip_tags($msg); ?>";
|
||||
var conf = <?php echo $js_confirm_msg; ?>;
|
||||
if (confirm(conf)) {
|
||||
document.location.replace("<?php echo $url1; ?>");
|
||||
document.location.replace(<?php echo $js_url1; ?>);
|
||||
} else {
|
||||
document.location.replace("<?php echo $url2; ?>");
|
||||
document.location.replace(<?php echo $js_url2; ?>);
|
||||
}
|
||||
</script>
|
||||
|
||||
@@ -49,4 +55,4 @@ if (confirm(conf)) {
|
||||
</noscript>
|
||||
|
||||
<?php
|
||||
include_once(G5_PATH.'/tail.sub.php');
|
||||
include_once(G5_PATH.'/tail.sub.php');
|
||||
|
||||
+2
-2
@@ -3,7 +3,7 @@ include_once('./_common.php');
|
||||
include_once(G5_CAPTCHA_PATH.'/captcha.lib.php');
|
||||
|
||||
if (!$config['cf_email_use'])
|
||||
alert_close('환경설정에서 \"메일발송 사용\"에 체크하셔야 메일을 발송할 수 있습니다.\\n\\n관리자에게 문의하시기 바랍니다.');
|
||||
alert_close('환경설정에서 "메일발송 사용"에 체크하셔야 메일을 발송할 수 있습니다.\\n\\n관리자에게 문의하시기 바랍니다.');
|
||||
|
||||
if (!$is_member && $config['cf_formmail_is_member'])
|
||||
alert_close('회원만 이용하실 수 있습니다.');
|
||||
@@ -52,4 +52,4 @@ $type_checked[$type] = 'checked';
|
||||
|
||||
include_once($member_skin_path.'/formmail.skin.php');
|
||||
|
||||
include_once(G5_PATH.'/tail.sub.php');
|
||||
include_once(G5_PATH.'/tail.sub.php');
|
||||
|
||||
+2
-2
@@ -38,10 +38,10 @@ if ($is_member) {
|
||||
sql_query($sql);
|
||||
|
||||
if (get_sql_affected_rows() <= 0) {
|
||||
alert(addcslashes($po['po_subject'], '"\\/').'에 이미 참여하셨습니다.', $result_url);
|
||||
alert($po['po_subject'].'에 이미 참여하셨습니다.', $result_url);
|
||||
}
|
||||
|
||||
insert_point($member['mb_id'], $po['po_point'], $po['po_id'] . '. ' . cut_str($po['po_subject'],20) . ' 투표 참여 ', '@poll', $po['po_id'], '투표');
|
||||
|
||||
//goto_url($g5['bbs_url'].'/poll_result.php?po_id='.$po_id.'&skin_dir='.$skin_dir);
|
||||
goto_url($result_url);
|
||||
goto_url($result_url);
|
||||
|
||||
@@ -174,11 +174,11 @@ for ($i=1; $i<=$upload_count; $i++) {
|
||||
// 서버에 설정된 값보다 큰파일을 업로드 한다면
|
||||
if ($filename) {
|
||||
if ($_FILES['bf_file']['error'][$i] == 1) {
|
||||
$file_upload_msg .= '\"'.$filename.'\" 파일의 용량이 서버에 설정('.$upload_max_filesize.')된 값보다 크므로 업로드 할 수 없습니다.\\n';
|
||||
$file_upload_msg .= '"'.$filename.'" 파일의 용량이 서버에 설정('.$upload_max_filesize.')된 값보다 크므로 업로드 할 수 없습니다.\\n';
|
||||
continue;
|
||||
}
|
||||
else if ($_FILES['bf_file']['error'][$i] != 0) {
|
||||
$file_upload_msg .= '\"'.$filename.'\" 파일이 정상적으로 업로드 되지 않았습니다.\\n';
|
||||
$file_upload_msg .= '"'.$filename.'" 파일이 정상적으로 업로드 되지 않았습니다.\\n';
|
||||
continue;
|
||||
}
|
||||
}
|
||||
@@ -186,7 +186,7 @@ for ($i=1; $i<=$upload_count; $i++) {
|
||||
if (is_uploaded_file($tmp_file)) {
|
||||
// 관리자가 아니면서 설정한 업로드 사이즈보다 크다면 건너뜀
|
||||
if (!$is_admin && $filesize > $qaconfig['qa_upload_size']) {
|
||||
$file_upload_msg .= '\"'.$filename.'\" 파일의 용량('.number_format($filesize).' 바이트)이 게시판에 설정('.number_format($qaconfig['qa_upload_size']).' 바이트)된 값보다 크므로 업로드 하지 않습니다.\\n';
|
||||
$file_upload_msg .= '"'.$filename.'" 파일의 용량('.number_format($filesize).' 바이트)이 게시판에 설정('.number_format($qaconfig['qa_upload_size']).' 바이트)된 값보다 크므로 업로드 하지 않습니다.\\n';
|
||||
continue;
|
||||
}
|
||||
|
||||
@@ -482,4 +482,4 @@ else
|
||||
if ($file_upload_msg)
|
||||
alert($file_upload_msg, $result_url);
|
||||
else
|
||||
goto_url($result_url);
|
||||
goto_url($result_url);
|
||||
|
||||
@@ -678,8 +678,11 @@ if(isset($_SESSION['ss_cert_hash'])) unset($_SESSION['ss_cert_hash']);
|
||||
if(isset($_SESSION['ss_cert_birth'])) unset($_SESSION['ss_cert_birth']);
|
||||
if(isset($_SESSION['ss_cert_adult'])) unset($_SESSION['ss_cert_adult']);
|
||||
|
||||
if ($msg)
|
||||
echo '<script>alert(\''.$msg.'\');</script>';
|
||||
if ($msg) {
|
||||
$js_replace = array('\\' => '\\\\', '"' => '\\"', "'" => '\\u0027', '/' => '\\/', "\r" => '\\r', "\n" => '\\n', "\t" => '\\t', '<' => '\\u003C', '>' => '\\u003E', '&' => '\\u0026', "\xE2\x80\xA8" => '\\u2028', "\xE2\x80\xA9" => '\\u2029');
|
||||
$js_msg = function_exists('get_js_safe_string') ? get_js_safe_string($msg) : '"'.strtr((string)$msg, $js_replace).'"';
|
||||
echo '<script>alert('.$js_msg.');</script>';
|
||||
}
|
||||
|
||||
run_event('register_form_update_after', $mb_id, $w);
|
||||
|
||||
|
||||
@@ -6,7 +6,10 @@ include_once(G5_PATH.'/head.sub.php');
|
||||
if (!$is_member)
|
||||
{
|
||||
$href = './login.php?'.$qstr.'&url='.urlencode(get_pretty_url($bo_table, $wr_id));
|
||||
echo '<script> alert(\'회원만 접근 가능합니다.\'); top.location.href = \''.str_replace('&', '&', $href).'\'; </script>';
|
||||
$href = str_replace('&', '&', $href);
|
||||
$js_replace = array('\\' => '\\\\', '"' => '\\"', "'" => '\\u0027', '/' => '\\/', "\r" => '\\r', "\n" => '\\n', "\t" => '\\t', '<' => '\\u003C', '>' => '\\u003E', '&' => '\\u0026', "\xE2\x80\xA8" => '\\u2028', "\xE2\x80\xA9" => '\\u2029');
|
||||
$js_href = function_exists('get_js_safe_string') ? get_js_safe_string($href) : '"'.strtr((string)$href, $js_replace).'"';
|
||||
echo '<script> alert(\'회원만 접근 가능합니다.\'); top.location.href = '.$js_href.'; </script>';
|
||||
exit;
|
||||
}
|
||||
|
||||
@@ -115,4 +118,4 @@ delete_cache_latest($bo_table);
|
||||
<noscript>
|
||||
<p>이 글을 스크랩 하였습니다.</p>
|
||||
<a href="./scrap.php">스크랩 확인하기</a>
|
||||
</noscript>
|
||||
</noscript>
|
||||
|
||||
@@ -528,11 +528,11 @@ if(isset($_FILES['bf_file']['name']) && is_array($_FILES['bf_file']['name'])) {
|
||||
// 서버에 설정된 값보다 큰파일을 업로드 한다면
|
||||
if ($filename) {
|
||||
if ($_FILES['bf_file']['error'][$i] == 1) {
|
||||
$file_upload_msg .= '\"'.$filename.'\" 파일의 용량이 서버에 설정('.$upload_max_filesize.')된 값보다 크므로 업로드 할 수 없습니다.\\n';
|
||||
$file_upload_msg .= '"'.$filename.'" 파일의 용량이 서버에 설정('.$upload_max_filesize.')된 값보다 크므로 업로드 할 수 없습니다.\\n';
|
||||
continue;
|
||||
}
|
||||
else if ($_FILES['bf_file']['error'][$i] != 0) {
|
||||
$file_upload_msg .= '\"'.$filename.'\" 파일이 정상적으로 업로드 되지 않았습니다.\\n';
|
||||
$file_upload_msg .= '"'.$filename.'" 파일이 정상적으로 업로드 되지 않았습니다.\\n';
|
||||
continue;
|
||||
}
|
||||
}
|
||||
@@ -540,7 +540,7 @@ if(isset($_FILES['bf_file']['name']) && is_array($_FILES['bf_file']['name'])) {
|
||||
if (is_uploaded_file($tmp_file)) {
|
||||
// 관리자가 아니면서 설정한 업로드 사이즈보다 크다면 건너뜀
|
||||
if (!$is_admin && $filesize > $board['bo_upload_size']) {
|
||||
$file_upload_msg .= '\"'.$filename.'\" 파일의 용량('.number_format($filesize).' 바이트)이 게시판에 설정('.number_format($board['bo_upload_size']).' 바이트)된 값보다 크므로 업로드 하지 않습니다.\\n';
|
||||
$file_upload_msg .= '"'.$filename.'" 파일의 용량('.number_format($filesize).' 바이트)이 게시판에 설정('.number_format($board['bo_upload_size']).' 바이트)된 값보다 크므로 업로드 하지 않습니다.\\n';
|
||||
continue;
|
||||
}
|
||||
|
||||
|
||||
+13
-5
@@ -112,11 +112,14 @@ function goto_url($url)
|
||||
if (!headers_sent())
|
||||
header('Location: '.$url);
|
||||
else {
|
||||
$js_replace = array('\\' => '\\\\', '"' => '\\"', "'" => '\\u0027', '/' => '\\/', "\r" => '\\r', "\n" => '\\n', "\t" => '\\t', '<' => '\\u003C', '>' => '\\u003E', '&' => '\\u0026', "\xE2\x80\xA8" => '\\u2028', "\xE2\x80\xA9" => '\\u2029');
|
||||
$js_url = function_exists('get_js_safe_string') ? get_js_safe_string($url) : '"'.strtr((string)$url, $js_replace).'"';
|
||||
$html_url = htmlspecialchars($url, ENT_QUOTES);
|
||||
echo '<script>';
|
||||
echo 'location.replace("'.$url.'");';
|
||||
echo 'location.replace('.$js_url.');';
|
||||
echo '</script>';
|
||||
echo '<noscript>';
|
||||
echo '<meta http-equiv="refresh" content="0;url='.$url.'" />';
|
||||
echo '<meta http-equiv="refresh" content="0;url='.$html_url.'" />';
|
||||
echo '</noscript>';
|
||||
}
|
||||
exit;
|
||||
@@ -3740,7 +3743,9 @@ function module_exec_check($exe, $type)
|
||||
}
|
||||
|
||||
if($error) {
|
||||
$error = '<script>alert("'.$error.'");</script>';
|
||||
$js_replace = array('\\' => '\\\\', '"' => '\\"', "'" => '\\u0027', '/' => '\\/', "\r" => '\\r', "\n" => '\\n', "\t" => '\\t', '<' => '\\u003C', '>' => '\\u003E', '&' => '\\u0026', "\xE2\x80\xA8" => '\\u2028', "\xE2\x80\xA9" => '\\u2029');
|
||||
$js_error = function_exists('get_js_safe_string') ? get_js_safe_string($error) : '"'.strtr((string)$error, $js_replace).'"';
|
||||
$error = '<script>alert('.$js_error.');</script>';
|
||||
}
|
||||
|
||||
return $error;
|
||||
@@ -4165,13 +4170,16 @@ function check_url_host($url, $msg='', $return_url=G5_URL, $is_redirect=false)
|
||||
if ((isset($p['scheme']) && $p['scheme']) || (isset($p['host']) && $p['host']) || $is_host_check) {
|
||||
//if ($p['host'].(isset($p['port']) ? ':'.$p['port'] : '') != $_SERVER['HTTP_HOST']) {
|
||||
if (run_replace('check_same_url_host', (($p['host'] != $host) || $is_host_check), $p, $host, $is_host_check, $return_url, $is_redirect)) {
|
||||
$js_replace = array('\\' => '\\\\', '"' => '\\"', "'" => '\\u0027', '/' => '\\/', "\r" => '\\r', "\n" => '\\n', "\t" => '\\t', '<' => '\\u003C', '>' => '\\u003E', '&' => '\\u0026', "\xE2\x80\xA8" => '\\u2028', "\xE2\x80\xA9" => '\\u2029');
|
||||
$js_return_url = function_exists('get_js_safe_string') ? get_js_safe_string($return_url) : '"'.strtr((string)$return_url, $js_replace).'"';
|
||||
$html_return_url = htmlspecialchars($return_url, ENT_QUOTES);
|
||||
echo '<script>'.PHP_EOL;
|
||||
echo 'alert("url에 타 도메인을 지정할 수 없습니다.");'.PHP_EOL;
|
||||
echo 'document.location.href = "'.$return_url.'";'.PHP_EOL;
|
||||
echo 'document.location.href = '.$js_return_url.';'.PHP_EOL;
|
||||
echo '</script>'.PHP_EOL;
|
||||
echo '<noscript>'.PHP_EOL;
|
||||
echo '<p>'.$msg.'</p>'.PHP_EOL;
|
||||
echo '<p><a href="'.$return_url.'">돌아가기</a></p>'.PHP_EOL;
|
||||
echo '<p><a href="'.$html_return_url.'">돌아가기</a></p>'.PHP_EOL;
|
||||
echo '</noscript>'.PHP_EOL;
|
||||
exit;
|
||||
}
|
||||
|
||||
+7
-3
@@ -1405,11 +1405,15 @@ function alert_opener($msg='', $url='')
|
||||
global $g5;
|
||||
|
||||
if (!$msg) $msg = '올바른 방법으로 이용해 주십시오.';
|
||||
$msg = strip_tags($msg);
|
||||
$js_replace = array('\\' => '\\\\', '"' => '\\"', "'" => '\\u0027', '/' => '\\/', "\r" => '\\r', "\n" => '\\n', "\t" => '\\t', '<' => '\\u003C', '>' => '\\u003E', '&' => '\\u0026', "\xE2\x80\xA8" => '\\u2028', "\xE2\x80\xA9" => '\\u2029');
|
||||
$js_msg = function_exists('get_js_safe_string') ? get_js_safe_string($msg) : '"'.strtr((string)$msg, $js_replace).'"';
|
||||
$js_url = function_exists('get_js_safe_string') ? get_js_safe_string($url) : '"'.strtr((string)$url, $js_replace).'"';
|
||||
|
||||
echo "<meta http-equiv=\"content-type\" content=\"text/html; charset=utf-8\">";
|
||||
echo "<script>";
|
||||
echo "alert(\"$msg\");";
|
||||
echo "opener.location.href=\"$url\";";
|
||||
echo "alert(".$js_msg.");";
|
||||
echo "opener.location.href=".$js_url.";";
|
||||
echo "self.close();";
|
||||
echo "</script>";
|
||||
exit;
|
||||
@@ -2976,4 +2980,4 @@ function is_coupon_downloaded($mb_id, $cz_id)
|
||||
|
||||
//==============================================================================
|
||||
// 쇼핑몰 라이브러리 모음 끝
|
||||
//==============================================================================;
|
||||
//==============================================================================;
|
||||
|
||||
@@ -81,16 +81,22 @@ set_session('ss_cert_adult', $adult);
|
||||
set_session('ss_cert_birth', $birth_day);
|
||||
set_session('ss_cert_sex', ($sex_code == '01' ? 'M' : 'F'));
|
||||
set_session('ss_cert_dupinfo', $mb_dupinfo);
|
||||
|
||||
$js_replace = array('\\' => '\\\\', '"' => '\\"', "'" => '\\u0027', '/' => '\\/', "\r" => '\\r', "\n" => '\\n', "\t" => '\\t', '<' => '\\u003C', '>' => '\\u003E', '&' => '\\u0026', "\xE2\x80\xA8" => '\\u2028', "\xE2\x80\xA9" => '\\u2029');
|
||||
$js_cert_type = function_exists('get_js_safe_string') ? get_js_safe_string($cert_type) : '"'.strtr((string)$cert_type, $js_replace).'"';
|
||||
$js_user_name = function_exists('get_js_safe_string') ? get_js_safe_string($user_name) : '"'.strtr((string)$user_name, $js_replace).'"';
|
||||
$js_phone_no = function_exists('get_js_safe_string') ? get_js_safe_string($phone_no) : '"'.strtr((string)$phone_no, $js_replace).'"';
|
||||
$js_md5_cert_no = function_exists('get_js_safe_string') ? get_js_safe_string($md5_cert_no) : '"'.strtr((string)$md5_cert_no, $js_replace).'"';
|
||||
?>
|
||||
<script>
|
||||
jQuery(function($) {
|
||||
var $opener = window.opener;
|
||||
if (!$opener) { window.close(); return; }
|
||||
|
||||
$opener.$("input[name=cert_type]").val(<?php echo get_js_safe_string($cert_type); ?>);
|
||||
$opener.$("input[name=mb_name]").val(<?php echo get_js_safe_string($user_name); ?>).attr("readonly", true);
|
||||
$opener.$("input[name=mb_hp]").val(<?php echo get_js_safe_string($phone_no); ?>).attr("readonly", true);
|
||||
$opener.$("input[name=cert_no]").val(<?php echo get_js_safe_string($md5_cert_no); ?>);
|
||||
$opener.$("input[name=cert_type]").val(<?php echo $js_cert_type; ?>);
|
||||
$opener.$("input[name=mb_name]").val(<?php echo $js_user_name; ?>).attr("readonly", true);
|
||||
$opener.$("input[name=mb_hp]").val(<?php echo $js_phone_no; ?>).attr("readonly", true);
|
||||
$opener.$("input[name=cert_no]").val(<?php echo $js_md5_cert_no; ?>);
|
||||
|
||||
alert("본인의 휴대폰번호로 확인 되었습니다.");
|
||||
|
||||
|
||||
@@ -98,7 +98,9 @@ if ($retcode == "B000") {
|
||||
echo ("<script>request();</script>");
|
||||
} else {
|
||||
//요청 실패 페이지로 리턴
|
||||
echo ("<script>alert(\"$retcode\"); self.close();</script>");
|
||||
$js_replace = array('\\' => '\\\\', '"' => '\\"', "'" => '\\u0027', '/' => '\\/', "\r" => '\\r', "\n" => '\\n', "\t" => '\\t', '<' => '\\u003C', '>' => '\\u003E', '&' => '\\u0026', "\xE2\x80\xA8" => '\\u2028', "\xE2\x80\xA9" => '\\u2029');
|
||||
$js_retcode = function_exists('get_js_safe_string') ? get_js_safe_string($retcode) : '"'.strtr((string)$retcode, $js_replace).'"';
|
||||
echo ("<script>alert(".$js_retcode."); self.close();</script>");
|
||||
}
|
||||
|
||||
include_once(G5_PATH.'/tail.sub.php');
|
||||
include_once(G5_PATH.'/tail.sub.php');
|
||||
|
||||
Reference in New Issue
Block a user