[security] ORDER BY sst/sod 화이트리스트 누락 Blind SQL Injection 수정

KVE-2026-0876 동일 패턴 추가 발견 5건 일괄 수정.

- shop/itemuselist.php / mobile/shop/itemuselist.php (상품후기 목록)
- shop/itemqalist.php / mobile/shop/itemqalist.php (상품문의 목록)
  → 비회원 접근 가능한 공개 페이지에서 sst/sod 가 ORDER BY 절에
    검증 없이 삽입되어 CASE WHEN/SLEEP 기반 blind SQLi 가능했음.
    sst 는 컬럼 화이트리스트, sod 는 asc/desc 정규식으로 검증.

- bbs/list.php (게시판 목록)
  → sst 는 wr_datetime/wr_hit/wr_good/wr_nogood 화이트리스트 적용
    되어 있으나 sod 가 검증 누락되어 ORDER BY 절에 함수 표현식
    삽입이 가능했음. sod 에 asc/desc 정규식 검증 추가.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
thisgun
2026-05-26 06:32:28 +00:00
co-authored by Claude Opus 4.7
parent a781b4aef3
commit 6b2f9e094c
5 changed files with 15 additions and 0 deletions
+3
View File
@@ -41,6 +41,9 @@ if (!$sst) {
$sst = "a.iq_id";
$sod = "desc";
}
// 정렬 컬럼/방향 화이트리스트
$sst = in_array($sst, array('a.iq_id', 'a.iq_datetime', 'a.it_id', 'b.it_name'), true) ? $sst : 'a.iq_id';
$sod = preg_match("/^(asc|desc)$/i", $sod) ? $sod : 'desc';
$sql_order = " order by $sst $sod ";
$sql = " select count(*) as cnt
+3
View File
@@ -41,6 +41,9 @@ if (!$sst) {
$sst = "a.is_id";
$sod = "desc";
}
// 정렬 컬럼/방향 화이트리스트
$sst = in_array($sst, array('a.is_id', 'a.is_datetime', 'a.is_score', 'a.it_id', 'b.it_name'), true) ? $sst : 'a.is_id';
$sod = preg_match("/^(asc|desc)$/i", $sod) ? $sod : 'desc';
$sql_order = " order by $sst $sod ";
$sql = " select count(*) as cnt