[security] ORDER BY sst/sod 화이트리스트 누락 Blind SQL Injection 수정
KVE-2026-0876 동일 패턴 추가 발견 5건 일괄 수정.
- shop/itemuselist.php / mobile/shop/itemuselist.php (상품후기 목록)
- shop/itemqalist.php / mobile/shop/itemqalist.php (상품문의 목록)
→ 비회원 접근 가능한 공개 페이지에서 sst/sod 가 ORDER BY 절에
검증 없이 삽입되어 CASE WHEN/SLEEP 기반 blind SQLi 가능했음.
sst 는 컬럼 화이트리스트, sod 는 asc/desc 정규식으로 검증.
- bbs/list.php (게시판 목록)
→ sst 는 wr_datetime/wr_hit/wr_good/wr_nogood 화이트리스트 적용
되어 있으나 sod 가 검증 누락되어 ORDER BY 절에 함수 표현식
삽입이 가능했음. sod 에 asc/desc 정규식 검증 추가.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.7
parent
a781b4aef3
commit
6b2f9e094c
@@ -41,6 +41,9 @@ if (!$sst) {
|
||||
$sst = "a.iq_id";
|
||||
$sod = "desc";
|
||||
}
|
||||
// 정렬 컬럼/방향 화이트리스트
|
||||
$sst = in_array($sst, array('a.iq_id', 'a.iq_datetime', 'a.it_id', 'b.it_name'), true) ? $sst : 'a.iq_id';
|
||||
$sod = preg_match("/^(asc|desc)$/i", $sod) ? $sod : 'desc';
|
||||
$sql_order = " order by $sst $sod ";
|
||||
|
||||
$sql = " select count(*) as cnt
|
||||
|
||||
@@ -41,6 +41,9 @@ if (!$sst) {
|
||||
$sst = "a.is_id";
|
||||
$sod = "desc";
|
||||
}
|
||||
// 정렬 컬럼/방향 화이트리스트
|
||||
$sst = in_array($sst, array('a.is_id', 'a.is_datetime', 'a.is_score', 'a.it_id', 'b.it_name'), true) ? $sst : 'a.is_id';
|
||||
$sod = preg_match("/^(asc|desc)$/i", $sod) ? $sod : 'desc';
|
||||
$sql_order = " order by $sst $sod ";
|
||||
|
||||
$sql = " select count(*) as cnt
|
||||
|
||||
Reference in New Issue
Block a user