security: KVE-2026-1899 KVE-2026-1900 KVE-2026-1909 입력 및 권한 검증 강화
상품 정렬값을 허용 목록으로 검증하고 관리자 권한 컨텍스트를 명확히 구분한다. 모바일 KCP의 Windows 명령 인자를 안전하게 조립하고 검증한다.
This commit is contained in:
+8
-14
@@ -1,22 +1,16 @@
|
||||
<?php
|
||||
include_once('../common.php');
|
||||
|
||||
if (isset($_REQUEST['sort']) && !preg_match("/(--|#|\/\*|\*\/)/", $_REQUEST['sort'])) {
|
||||
$sort = trim($_REQUEST['sort']);
|
||||
$sort = preg_replace("/[\<\>\'\"\\\'\\\"\%\=\(\)\s]/", "", $sort);
|
||||
} else {
|
||||
$sort = '';
|
||||
}
|
||||
|
||||
if (isset($_REQUEST['sortodr'])) {
|
||||
$sortodr = preg_match("/^(asc|desc)$/i", $sortodr) ? $sortodr : '';
|
||||
} else {
|
||||
$sortodr = '';
|
||||
}
|
||||
|
||||
if (!defined('G5_USE_SHOP') || !G5_USE_SHOP)
|
||||
die('<p>쇼핑몰 설치 후 이용해 주십시오.</p>');
|
||||
|
||||
$is_admin = get_super_admin_type($is_admin);
|
||||
|
||||
$request_sort = (isset($_REQUEST['sort']) && is_string($_REQUEST['sort'])) ? $_REQUEST['sort'] : '';
|
||||
$request_sortodr = (isset($_REQUEST['sortodr']) && is_string($_REQUEST['sortodr'])) ? $_REQUEST['sortodr'] : '';
|
||||
list($sort, $sortodr) = get_shop_item_sort($request_sort, $request_sortodr);
|
||||
unset($request_sort, $request_sortodr);
|
||||
|
||||
define('_SHOP_', true);
|
||||
define('_SHOP_COMMON_', true); // 모바일 페이지의 직접 접근을 막는 경우에 사용
|
||||
?>
|
||||
?>
|
||||
|
||||
+1
-6
@@ -5,11 +5,6 @@ $ev_id = isset($_GET['ev_id']) ? (int) $_GET['ev_id'] : 0;
|
||||
$skin = isset($_GET['skin']) ? clean_xss_tags($_GET['skin'], 1, 1) : '';
|
||||
$ca_id = isset($_GET['ca_id']) ? clean_xss_tags($_GET['ca_id'], 1, 1) : '';
|
||||
|
||||
// 상품 리스트에서 다른 필드로 정렬을 하려면 아래의 배열 코드에서 해당 필드를 추가하세요.
|
||||
if( isset($sort) && ! in_array($sort, array('it_name', 'it_sum_qty', 'it_price', 'it_use_avg', 'it_use_cnt', 'it_update_time')) ){
|
||||
$sort='';
|
||||
}
|
||||
|
||||
if (G5_IS_MOBILE) {
|
||||
include_once(G5_MSHOP_PATH.'/event.php');
|
||||
return;
|
||||
@@ -117,4 +112,4 @@ if (file_exists($timg))
|
||||
<!-- } 이벤트 끝 -->
|
||||
|
||||
<?php
|
||||
include_once('./_tail.php');
|
||||
include_once('./_tail.php');
|
||||
|
||||
+2
-2
@@ -38,7 +38,7 @@ if ($w == "u")
|
||||
|
||||
$it_id = $qa['it_id'];
|
||||
|
||||
if (!$is_admin && $qa['mb_id'] != $member['mb_id']) {
|
||||
if (!is_shop_resource_owner_or_super_admin($qa['mb_id'], $member['mb_id'], $is_admin)) {
|
||||
alert_close("자신의 상품문의만 수정이 가능합니다.");
|
||||
}
|
||||
|
||||
@@ -66,4 +66,4 @@ if(!file_exists($itemqaform_skin)) {
|
||||
include_once($itemqaform_skin);
|
||||
}
|
||||
|
||||
include_once(G5_PATH.'/tail.sub.php');
|
||||
include_once(G5_PATH.'/tail.sub.php');
|
||||
|
||||
@@ -37,7 +37,7 @@ if ($w == "") {
|
||||
$it_id = $use['it_id'];
|
||||
$is_score = $use['is_score'];
|
||||
|
||||
if (!$is_admin && $use['mb_id'] != $member['mb_id']) {
|
||||
if (!is_shop_resource_owner_or_super_admin($use['mb_id'], $member['mb_id'], $is_admin)) {
|
||||
alert_close("자신의 사용후기만 수정이 가능합니다.");
|
||||
}
|
||||
}
|
||||
@@ -62,4 +62,4 @@ if(!file_exists($itemuseform_skin)) {
|
||||
include_once($itemuseform_skin);
|
||||
}
|
||||
|
||||
include_once(G5_PATH.'/tail.sub.php');
|
||||
include_once(G5_PATH.'/tail.sub.php');
|
||||
|
||||
@@ -168,7 +168,7 @@
|
||||
{
|
||||
if (strtoupper(substr(PHP_OS, 0, 3)) === 'WIN')
|
||||
{
|
||||
// 실행 파일 경로와 인자를 분리하여 mf_exec 호출 → escapeshellarg 자동 적용 (KVE-2026-0859)
|
||||
// 실행 파일 경로와 인자를 분리하여 mf_exec 호출 → escapeshellarg 자동 적용
|
||||
$bin_exe = $home_dir.'/bin/pp_cli_exe';
|
||||
|
||||
$res_data = $this->mf_exec($bin_exe,
|
||||
@@ -276,10 +276,8 @@
|
||||
return $my_data;
|
||||
}
|
||||
|
||||
function mf_exec()
|
||||
function mf_build_exec_cmd( $arg )
|
||||
{
|
||||
$arg = func_get_args();
|
||||
|
||||
if ( is_array( $arg[0] ) ) $arg = $arg[0];
|
||||
|
||||
$exec_cmd = array_shift( $arg );
|
||||
@@ -289,8 +287,16 @@
|
||||
$exec_cmd .= " " . escapeshellarg( $i );
|
||||
}
|
||||
|
||||
return $exec_cmd;
|
||||
}
|
||||
|
||||
function mf_exec()
|
||||
{
|
||||
$arg = func_get_args();
|
||||
$exec_cmd = $this->mf_build_exec_cmd( $arg );
|
||||
|
||||
$rt = exec( $exec_cmd );
|
||||
|
||||
return $rt;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
+1
-9
@@ -4,14 +4,6 @@ include_once('./_common.php');
|
||||
$ca_id = isset($_REQUEST['ca_id']) ? safe_replace_regex($_REQUEST['ca_id'], 'ca_id') : '';
|
||||
$skin = isset($_REQUEST['skin']) ? safe_replace_regex($_REQUEST['skin'], 'skin') : '';
|
||||
|
||||
// 상품 리스트에서 다른 필드로 정렬을 하려면 아래의 배열 코드에서 해당 필드를 추가하세요.
|
||||
if( isset($sort) && ! in_array($sort, array('it_name', 'it_sum_qty', 'it_price', 'it_use_avg', 'it_use_cnt', 'it_update_time')) ){
|
||||
$sort='';
|
||||
}
|
||||
if( !isset($sortodr) || !in_array(strtolower($sortodr), array('asc', 'desc')) ){
|
||||
$sortodr='';
|
||||
}
|
||||
|
||||
if (G5_IS_MOBILE) {
|
||||
include_once(G5_MSHOP_PATH.'/list.php');
|
||||
return;
|
||||
@@ -181,4 +173,4 @@ if ($ca['ca_include_tail'] && is_include_path_check($ca['ca_include_tail'])
|
||||
else
|
||||
include_once(G5_SHOP_PATH.'/_tail.php');
|
||||
|
||||
echo "\n<!-- {$ca['ca_skin']} -->\n";
|
||||
echo "\n<!-- {$ca['ca_skin']} -->\n";
|
||||
|
||||
+1
-3
@@ -1,8 +1,6 @@
|
||||
<?php
|
||||
include_once('./_common.php');
|
||||
|
||||
// 상품 리스트에서 다른 필드로 정렬을 하려면 아래의 배열 코드에서 해당 필드를 추가하세요.
|
||||
$sort = (isset($_REQUEST['sort']) && in_array($_REQUEST['sort'], array('it_name', 'it_sum_qty', 'it_price', 'it_use_avg', 'it_use_cnt', 'it_update_time'))) ? $_REQUEST['sort'] : '';
|
||||
$type = isset($_REQUEST['type']) ? (int) preg_replace("/[^0-9]/", "", $_REQUEST['type']) : 1;
|
||||
|
||||
if (G5_IS_MOBILE) {
|
||||
@@ -83,4 +81,4 @@ else
|
||||
$qstr .= '&type='.$type.'&sort='.$sort;
|
||||
echo get_paging($config['cf_write_pages'], $page, $total_page, "{$_SERVER['SCRIPT_NAME']}?$qstr&page=");
|
||||
|
||||
include_once('./_tail.php');
|
||||
include_once('./_tail.php');
|
||||
|
||||
Reference in New Issue
Block a user