[security]KVE-2026-0710 그누보드5 SQL Injection 수정
This commit is contained in:
@@ -19,8 +19,8 @@ $mb_certify = isset($_POST['mb_certify']) ? preg_replace('/[^0-9a-z_]/i', ''
|
||||
$mb_zip = isset($_POST['mb_zip']) ? preg_replace('/[^0-9a-z_]/i', '', $_POST['mb_zip']) : '';
|
||||
|
||||
// 광고성 정보 수신
|
||||
$mb_marketing_agree = isset($_POST['mb_marketing_agree']) ? clean_xss_tags($_POST['mb_marketing_agree'], 1, 1) : '0';
|
||||
$mb_thirdparty_agree = isset($_POST['mb_thirdparty_agree']) ? clean_xss_tags($_POST['mb_thirdparty_agree'], 1, 1) : '0';
|
||||
$mb_marketing_agree = isset($_POST['mb_marketing_agree']) ? addslashes(clean_xss_tags(stripslashes($_POST['mb_marketing_agree']), 1, 1)) : '0';
|
||||
$mb_thirdparty_agree = isset($_POST['mb_thirdparty_agree']) ? addslashes(clean_xss_tags(stripslashes($_POST['mb_thirdparty_agree']), 1, 1)) : '0';
|
||||
|
||||
// 관리자가 자동등록방지를 사용해야 할 경우 ( 회원의 비밀번호 변경시 캡챠를 체크한다 )
|
||||
if ($mb_password) {
|
||||
@@ -84,9 +84,9 @@ for ($i = 1; $i <= 10; $i++) {
|
||||
|
||||
foreach ($check_keys as $key) {
|
||||
if( in_array($key, array('mb_signature', 'mb_profile')) ){
|
||||
$posts[$key] = isset($_POST[$key]) ? clean_xss_tags($_POST[$key], 1, 1, 0, 0) : '';
|
||||
$posts[$key] = isset($_POST[$key]) ? addslashes(clean_xss_tags(stripslashes($_POST[$key]), 1, 1, 0, 0)) : '';
|
||||
} else {
|
||||
$posts[$key] = isset($_POST[$key]) ? clean_xss_tags($_POST[$key], 1, 1) : '';
|
||||
$posts[$key] = isset($_POST[$key]) ? addslashes(clean_xss_tags(stripslashes($_POST[$key]), 1, 1)) : '';
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
+1
-1
@@ -1,7 +1,7 @@
|
||||
<?php
|
||||
include_once('./_common.php');
|
||||
|
||||
$mb_id = isset($_REQUEST['mb_id']) ? clean_xss_tags($_REQUEST['mb_id'], 1, 1) : '';
|
||||
$mb_id = isset($_REQUEST['mb_id']) ? addslashes(clean_xss_tags(stripslashes($_REQUEST['mb_id']), 1, 1)) : '';
|
||||
|
||||
$sql = " select mb_id, mb_email, mb_datetime from {$g5['member_table']} where mb_id = '{$mb_id}' ";
|
||||
$row = sql_fetch($sql);
|
||||
|
||||
+2
-2
@@ -13,8 +13,8 @@ if (!$member['mb_open'] && $is_admin != 'super' && $member['mb_id'] != $mb_id) {
|
||||
}
|
||||
|
||||
$content = "";
|
||||
$me_recv_mb_id = isset($_REQUEST['me_recv_mb_id']) ? clean_xss_tags($_REQUEST['me_recv_mb_id'], 1, 1) : '';
|
||||
$me_id = isset($_REQUEST['me_id']) ? clean_xss_tags($_REQUEST['me_id'], 1, 1) : '';
|
||||
$me_recv_mb_id = isset($_REQUEST['me_recv_mb_id']) ? addslashes(clean_xss_tags(stripslashes($_REQUEST['me_recv_mb_id']), 1, 1)) : '';
|
||||
$me_id = isset($_REQUEST['me_id']) ? addslashes(clean_xss_tags(stripslashes($_REQUEST['me_id']), 1, 1)) : '';
|
||||
|
||||
// 탈퇴한 회원에게 쪽지 보낼 수 없음
|
||||
if ($me_recv_mb_id)
|
||||
|
||||
@@ -5,7 +5,7 @@ include_once(G5_CAPTCHA_PATH.'/captcha.lib.php');
|
||||
$g5['title'] = '메일인증 메일주소 변경';
|
||||
include_once('./_head.php');
|
||||
|
||||
$mb_id = isset($_GET['mb_id']) ? substr(clean_xss_tags($_GET['mb_id']), 0, 20) : '';
|
||||
$mb_id = isset($_GET['mb_id']) ? substr(addslashes(clean_xss_tags(stripslashes($_GET['mb_id']), 1, 1)), 0, 20) : '';
|
||||
$sql = " select mb_email, mb_datetime, mb_ip, mb_email_certify, mb_id from {$g5['member_table']} where mb_id = '{$mb_id}' ";
|
||||
$mb = sql_fetch($sql);
|
||||
|
||||
@@ -18,7 +18,7 @@ if (substr($mb['mb_email_certify'],0,1)!=0) {
|
||||
}
|
||||
|
||||
$ckey = isset($_GET['ckey']) ? trim($_GET['ckey']) : '';
|
||||
$key = function_exists('get_email_cert_key') ? get_email_cert_key($mb_id, $mb['mb_datetime']) : md5($mb['mb_ip'].$mb['mb_datetime']);
|
||||
$key = get_email_cert_key($mb_id, $mb['mb_datetime']);
|
||||
|
||||
if(!$ckey || $ckey !== $key)
|
||||
alert('올바른 방법으로 이용해 주십시오.', G5_URL);
|
||||
|
||||
@@ -18,7 +18,7 @@ if (substr_count($wr_content, "&#") > 50) {
|
||||
$w = isset($_POST['w']) ? clean_xss_tags($_POST['w']) : '';
|
||||
$wr_name = isset($_POST['wr_name']) ? addslashes(clean_xss_tags(stripslashes(trim($_POST['wr_name'])))) : '';
|
||||
$wr_name = preg_replace("#[\\\]+$#", "", $wr_name);
|
||||
$wr_secret = isset($_POST['wr_secret']) ? clean_xss_tags($_POST['wr_secret']) : '';
|
||||
$wr_secret = isset($_POST['wr_secret']) ? addslashes(clean_xss_tags(stripslashes($_POST['wr_secret']))) : '';
|
||||
$wr_email = $wr_subject = '';
|
||||
$reply_array = array();
|
||||
|
||||
|
||||
Reference in New Issue
Block a user