security: KVE-2026-1899 KVE-2026-1900 KVE-2026-1909 입력 및 권한 검증 강화

상품 정렬값을 허용 목록으로 검증하고 관리자 권한 컨텍스트를 명확히 구분한다.

모바일 KCP의 Windows 명령 인자를 안전하게 조립하고 검증한다.
This commit is contained in:
whitedot
2026-09-01 11:40:15 +09:00
parent 375a8336e8
commit 71209fc7c9
40 changed files with 185 additions and 148 deletions
+8 -1
View File
@@ -35,9 +35,16 @@
- `chore`: 기능과 직접 관련 없는 유지보수 작업 - `chore`: 기능과 직접 관련 없는 유지보수 작업
- `revert`: 이전 변경 되돌리기 - `revert`: 이전 변경 되돌리기
### 보안 이슈 식별자
- KVE, CVE 등 식별자가 부여된 보안 이슈를 조치하는 커밋은 제목에 관련 식별자를 반드시 병기한다.
- 식별자는 `security:` 접두어 바로 뒤에 원문 그대로 작성한다.
- 하나의 커밋이 여러 보안 이슈를 함께 조치하면 관련 식별자를 모두 병기한다.
- 예: `security: KVE-2026-1909 모바일 KCP Windows 명령 인자 주입 차단`
### 작성 예시 ### 작성 예시
- `docs: Git과 압축파일 설치 절차를 구분해 README에 안내` - `docs: Git과 압축파일 설치 절차를 구분해 README에 안내`
- `fix: 품목 일부 취소 시 PG 취소금액 불일치 수정` - `fix: 품목 일부 취소 시 PG 취소금액 불일치 수정`
- `security: 상품 정렬값 화이트리스트 검증으로 SQL 삽입 차단` - `security: KVE-2026-1899 상품 정렬값 화이트리스트 검증으로 SQL 삽입 차단`
- `refactor: 객체 캐시의 유형별 저장 키 생성 로직 분리` - `refactor: 객체 캐시의 유형별 저장 키 생성 로직 분리`
+3 -1
View File
@@ -1,6 +1,8 @@
<?php <?php
include_once('./_common.php'); include_once('./_common.php');
$is_admin = get_super_admin_type($is_admin);
if($is_guest) if($is_guest)
alert('회원이시라면 로그인 후 이용해 주십시오.', G5_URL); alert('회원이시라면 로그인 후 이용해 주십시오.', G5_URL);
@@ -93,4 +95,4 @@ for($i=0; $i<$count; $i++) {
*/ */
run_event('qa_delete', $tmp_array, $deleted); run_event('qa_delete', $tmp_array, $deleted);
goto_url(G5_BBS_URL.'/qalist.php'.preg_replace('/^&amp;/', '?', $qstr)); goto_url(G5_BBS_URL.'/qalist.php'.preg_replace('/^&amp;/', '?', $qstr));
+3 -1
View File
@@ -1,6 +1,8 @@
<?php <?php
include_once('./_common.php'); include_once('./_common.php');
$is_admin = get_super_admin_type($is_admin);
// clean the output buffer // clean the output buffer
ob_end_clean(); ob_end_clean();
@@ -85,4 +87,4 @@ while(!feof($fp)) {
usleep(1000); usleep(1000);
} }
fclose ($fp); fclose ($fp);
flush(); flush();
+6 -4
View File
@@ -1,13 +1,15 @@
<?php <?php
include_once('./_common.php'); include_once('./_common.php');
$is_admin = get_super_admin_type($is_admin);
if($is_guest) if($is_guest)
alert('회원이시라면 로그인 후 이용해 보십시오.', './login.php?url='.urlencode(G5_BBS_URL.'/qalist.php')); alert('회원이시라면 로그인 후 이용해 보십시오.', './login.php?url='.urlencode(G5_BBS_URL.'/qalist.php'));
$qaconfig = get_qa_config(); $qaconfig = get_qa_config();
$token = ''; $token = '';
if( $is_admin ){ if($is_admin === 'super') {
$token = _token(); $token = _token();
set_session('ss_qa_delete_token', $token); set_session('ss_qa_delete_token', $token);
} }
@@ -16,7 +18,7 @@ $g5['title'] = $qaconfig['qa_title'];
include_once('./qahead.php'); include_once('./qahead.php');
$skin_file = $qa_skin_path.'/list.skin.php'; $skin_file = $qa_skin_path.'/list.skin.php';
$is_auth = $is_admin ? true : false; $is_auth = ($is_admin === 'super');
$category_option = ''; $category_option = '';
@@ -132,7 +134,7 @@ if(is_file($skin_file)) {
$is_checkbox = false; $is_checkbox = false;
$admin_href = ''; $admin_href = '';
if($is_admin) { if($is_admin === 'super') {
$is_checkbox = true; $is_checkbox = true;
$admin_href = G5_ADMIN_URL.'/qa_config.php'; $admin_href = G5_ADMIN_URL.'/qa_config.php';
} }
@@ -148,4 +150,4 @@ if(is_file($skin_file)) {
echo '<div>'.str_replace(G5_PATH.'/', '', $skin_file).'이 존재하지 않습니다.</div>'; echo '<div>'.str_replace(G5_PATH.'/', '', $skin_file).'이 존재하지 않습니다.</div>';
} }
include_once('./qatail.php'); include_once('./qatail.php');
+5 -3
View File
@@ -2,6 +2,8 @@
include_once('./_common.php'); include_once('./_common.php');
include_once(G5_EDITOR_LIB); include_once(G5_EDITOR_LIB);
$is_admin = get_super_admin_type($is_admin);
$qa_id = isset($_REQUEST['qa_id']) ? (int) $_REQUEST['qa_id'] : 0; $qa_id = isset($_REQUEST['qa_id']) ? (int) $_REQUEST['qa_id'] : 0;
if($is_guest) if($is_guest)
@@ -115,7 +117,7 @@ if(is_file($skin_file)) {
} }
*/ */
if(($view['qa_type'] && $is_admin) || (!$view['qa_type'] && $view['qa_status'] == 0)) { if(($view['qa_type'] && $is_admin === 'super') || (!$view['qa_type'] && $view['qa_status'] == 0)) {
$update_href = G5_BBS_URL.'/qawrite.php?w=u&amp;qa_id='.$view['qa_id'].$qstr; $update_href = G5_BBS_URL.'/qawrite.php?w=u&amp;qa_id='.$view['qa_id'].$qstr;
$delete_href = G5_BBS_URL.'/qadelete.php?qa_id='.$view['qa_id'].'&amp;token='.$token.$qstr; $delete_href = G5_BBS_URL.'/qadelete.php?qa_id='.$view['qa_id'].'&amp;token='.$token.$qstr;
} }
@@ -131,7 +133,7 @@ if(is_file($skin_file)) {
and qa_parent = '{$view['qa_id']}' "; and qa_parent = '{$view['qa_id']}' ";
$answer = sql_fetch($sql); $answer = sql_fetch($sql);
if($is_admin) { if($is_admin === 'super') {
$answer_update_href = G5_BBS_URL.'/qawrite.php?w=u&amp;qa_id='.$answer['qa_id'].$qstr; $answer_update_href = G5_BBS_URL.'/qawrite.php?w=u&amp;qa_id='.$answer['qa_id'].$qstr;
$answer_delete_href = G5_BBS_URL.'/qadelete.php?qa_id='.$answer['qa_id'].'&amp;token='.$token.$qstr; $answer_delete_href = G5_BBS_URL.'/qadelete.php?qa_id='.$answer['qa_id'].'&amp;token='.$token.$qstr;
} }
@@ -216,4 +218,4 @@ if(is_file($skin_file)) {
echo '<div>'.str_replace(G5_PATH.'/', '', $skin_file).'이 존재하지 않습니다.</div>'; echo '<div>'.str_replace(G5_PATH.'/', '', $skin_file).'이 존재하지 않습니다.</div>';
} }
include_once('./qatail.php'); include_once('./qatail.php');
+7 -5
View File
@@ -2,6 +2,8 @@
include_once('./_common.php'); include_once('./_common.php');
include_once(G5_EDITOR_LIB); include_once(G5_EDITOR_LIB);
$is_admin = get_super_admin_type($is_admin);
if($w != '' && $w != 'u' && $w != 'r') { if($w != '' && $w != 'u' && $w != 'r') {
alert('올바른 방법으로 이용해 주십시오.'); alert('올바른 방법으로 이용해 주십시오.');
} }
@@ -30,7 +32,7 @@ if(is_file($skin_file)) {
if($w == 'u' || $w == 'r') { if($w == 'u' || $w == 'r') {
$sql = " select * from {$g5['qa_content_table']} where qa_id = '$qa_id' "; $sql = " select * from {$g5['qa_content_table']} where qa_id = '$qa_id' ";
if(!$is_admin) { if($is_admin !== 'super') {
$sql .= " and mb_id = '{$member['mb_id']}' "; $sql .= " and mb_id = '{$member['mb_id']}' ";
} }
@@ -40,7 +42,7 @@ if(is_file($skin_file)) {
if(!$write['qa_id']) if(!$write['qa_id'])
alert('게시글이 존재하지 않습니다.\\n삭제되었거나 자신의 글이 아닌 경우입니다.'); alert('게시글이 존재하지 않습니다.\\n삭제되었거나 자신의 글이 아닌 경우입니다.');
if(!$is_admin) { if($is_admin !== 'super') {
if($write['qa_type'] == 0 && $write['qa_status'] == 1) if($write['qa_type'] == 0 && $write['qa_status'] == 1)
alert('답변이 등록된 문의글은 수정할 수 없습니다.'); alert('답변이 등록된 문의글은 수정할 수 없습니다.');
@@ -117,7 +119,7 @@ if(is_file($skin_file)) {
if($w == '' || $w == 'r') if($w == '' || $w == 'r')
$write['qa_email'] = $member['mb_email']; $write['qa_email'] = $member['mb_email'];
if($w == 'u' && $is_admin && $write['qa_type']) if($w == 'u' && $is_admin === 'super' && $write['qa_type'])
$is_email = false; $is_email = false;
} }
@@ -132,7 +134,7 @@ if(is_file($skin_file)) {
if($w == '' || $w == 'r') if($w == '' || $w == 'r')
$write['qa_hp'] = $member['mb_hp']; $write['qa_hp'] = $member['mb_hp'];
if($w == 'u' && $is_admin && $write['qa_type']) if($w == 'u' && $is_admin === 'super' && $write['qa_type'])
$is_hp = false; $is_hp = false;
} }
@@ -145,4 +147,4 @@ if(is_file($skin_file)) {
echo '<div>'.str_replace(G5_PATH.'/', '', $skin_file).'이 존재하지 않습니다.</div>'; echo '<div>'.str_replace(G5_PATH.'/', '', $skin_file).'이 존재하지 않습니다.</div>';
} }
include_once('./qatail.php'); include_once('./qatail.php');
+4 -2
View File
@@ -1,6 +1,8 @@
<?php <?php
include_once('./_common.php'); include_once('./_common.php');
$is_admin = get_super_admin_type($is_admin);
/*========================== /*==========================
$w == a : 답변 $w == a : 답변
$w == r : 추가질문 $w == r : 추가질문
@@ -185,8 +187,8 @@ for ($i=1; $i<=$upload_count; $i++) {
} }
if (is_uploaded_file($tmp_file)) { if (is_uploaded_file($tmp_file)) {
// 관리자가 아니면서 설정한 업로드 사이즈보다 크다면 건너뜀 // 최고관리자가 아니면서 설정한 업로드 사이즈보다 크다면 건너뜀
if (!$is_admin && $filesize > $qaconfig['qa_upload_size']) { if ($is_admin !== 'super' && $filesize > $qaconfig['qa_upload_size']) {
$file_upload_msg .= '"'.$filename.'" 파일의 용량('.number_format($filesize).' 바이트)이 게시판에 설정('.number_format($qaconfig['qa_upload_size']).' 바이트)된 값보다 크므로 업로드 하지 않습니다.\\n'; $file_upload_msg .= '"'.$filename.'" 파일의 용량('.number_format($filesize).' 바이트)이 게시판에 설정('.number_format($qaconfig['qa_upload_size']).' 바이트)된 값보다 크므로 업로드 하지 않습니다.\\n';
continue; continue;
} }
+7
View File
@@ -20,6 +20,13 @@ function get_microtime()
} }
// 게시판/그룹 관리자 문맥을 제외하고 최고관리자 권한만 반환
function get_super_admin_type($admin_type)
{
return $admin_type === 'super' ? 'super' : '';
}
// 한페이지에 보여줄 행, 현재페이지, 총페이지수, URL // 한페이지에 보여줄 행, 현재페이지, 총페이지수, URL
function get_paging($write_pages, $cur_page, $total_page, $url, $add="") function get_paging($write_pages, $cur_page, $total_page, $url, $add="")
{ {
+41 -1
View File
@@ -26,6 +26,46 @@ function get_shop_uid($type, $id, $time, $ip)
return hash_hmac('sha256', $payload, $key); return hash_hmac('sha256', $payload, $key);
} }
/**
* 상품 목록 정렬 요청을 허용된 DB 컬럼과 방향으로 변환한다.
*
* @param mixed $sort 외부 정렬 키
* @param mixed $sortodr 외부 정렬 방향
* @return array 검증된 정렬 컬럼과 방향. 잘못된 입력이면 모두 빈 문자열
*/
function get_shop_item_sort($sort, $sortodr)
{
$sort_columns = array(
'it_name' => 'it_name',
'it_sum_qty' => 'it_sum_qty',
'it_price' => 'it_price',
'it_use_avg' => 'it_use_avg',
'it_use_cnt' => 'it_use_cnt',
'it_update_time' => 'it_update_time',
);
if (!is_string($sort) || !isset($sort_columns[$sort])) {
return array('', '');
}
if (!is_string($sortodr)) {
return array('', '');
}
$sortodr = strtolower($sortodr);
if (!in_array($sortodr, array('asc', 'desc'), true)) {
return array('', '');
}
return array($sort_columns[$sort], $sortodr);
}
// 쇼핑몰 리소스 소유자 또는 최고관리자인지 확인
function is_shop_resource_owner_or_super_admin($owner_id, $member_id, $admin_type)
{
return $admin_type === 'super' || ($member_id !== '' && $owner_id === $member_id);
}
/** /**
* 현금영수증 발급 또는 조회에 대한 검증 * 현금영수증 발급 또는 조회에 대한 검증
* *
@@ -2094,7 +2134,7 @@ function check_itemuse_write($it_id, $mb_id, $close=true)
{ {
global $g5, $default, $is_admin; global $g5, $default, $is_admin;
if(!$is_admin && $default['de_item_use_write']) if($is_admin !== 'super' && $default['de_item_use_write'])
{ {
$sql = " select count(*) as cnt $sql = " select count(*) as cnt
from {$g5['g5_shop_cart_table']} from {$g5['g5_shop_cart_table']}
+9 -15
View File
@@ -1,20 +1,14 @@
<?php <?php
include_once('../../common.php'); include_once('../../common.php');
// SQL 주석 토큰 차단 추가 — 데스크톱 shop/_common.php 와 동일 패턴
if (isset($_REQUEST['sort']) && !preg_match("/(--|#|\/\*|\*\/)/", $_REQUEST['sort'])) {
$sort = trim($_REQUEST['sort']);
$sort = preg_replace("/[\<\>\'\"\\\'\\\"\%\=\(\)\s]/", "", $sort);
} else {
$sort = '';
}
if (isset($_REQUEST['sortodr'])) {
$sortodr = preg_match("/^(asc|desc)$/i", $sortodr) ? $sortodr : '';
} else {
$sortodr = '';
}
if (!defined('G5_USE_SHOP') || !G5_USE_SHOP) if (!defined('G5_USE_SHOP') || !G5_USE_SHOP)
die('<p>쇼핑몰 설치 후 이용해 주십시오.</p>'); die('<p>쇼핑몰 설치 후 이용해 주십시오.</p>');
define('_SHOP_', true);
$is_admin = get_super_admin_type($is_admin);
$request_sort = (isset($_REQUEST['sort']) && is_string($_REQUEST['sort'])) ? $_REQUEST['sort'] : '';
$request_sortodr = (isset($_REQUEST['sortodr']) && is_string($_REQUEST['sortodr'])) ? $_REQUEST['sortodr'] : '';
list($sort, $sortodr) = get_shop_item_sort($request_sort, $request_sortodr);
unset($request_sort, $request_sortodr);
define('_SHOP_', true);
+1 -1
View File
@@ -93,4 +93,4 @@ echo '<div id="sev_thtml">'.conv_content($ev['ev_tail_html'], 1).'</div>';
</div> </div>
<?php <?php
include_once(G5_MSHOP_PATH.'/_tail.php'); include_once(G5_MSHOP_PATH.'/_tail.php');
+2 -2
View File
@@ -31,7 +31,7 @@ if ($w == "u")
$it_id = $qa['it_id']; $it_id = $qa['it_id'];
if (!$is_admin && $qa['mb_id'] != $member['mb_id']) { if (!is_shop_resource_owner_or_super_admin($qa['mb_id'], $member['mb_id'], $is_admin)) {
alert_close("자신의 상품문의만 수정이 가능합니다."); alert_close("자신의 상품문의만 수정이 가능합니다.");
} }
@@ -59,4 +59,4 @@ if(!file_exists($itemqaform_skin)) {
include_once($itemqaform_skin); include_once($itemqaform_skin);
} }
include_once(G5_PATH.'/tail.sub.php'); include_once(G5_PATH.'/tail.sub.php');
+2 -2
View File
@@ -29,7 +29,7 @@ if ($w == "") {
$it_id = $use['it_id']; $it_id = $use['it_id'];
$is_score = $use['is_score']; $is_score = $use['is_score'];
if (!$is_admin && $use['mb_id'] != $member['mb_id']) { if (!is_shop_resource_owner_or_super_admin($use['mb_id'], $member['mb_id'], $is_admin)) {
alert_close("자신의 사용후기만 수정이 가능합니다."); alert_close("자신의 사용후기만 수정이 가능합니다.");
} }
} }
@@ -54,4 +54,4 @@ if(!file_exists($itemuseform_skin)) {
include_once($itemuseform_skin); include_once($itemuseform_skin);
} }
include_once(G5_PATH.'/tail.sub.php'); include_once(G5_PATH.'/tail.sub.php');
+15 -9
View File
@@ -168,9 +168,10 @@
{ {
if (strtoupper(substr(PHP_OS, 0, 3)) === 'WIN') if (strtoupper(substr(PHP_OS, 0, 3)) === 'WIN')
{ {
$bin_exe = $home_dir.'/bin/pp_cli_exe '; // 실행 파일 경로와 인자를 분리하여 mf_exec 호출 → escapeshellarg 자동 적용
$bin_exe = $home_dir.'/bin/pp_cli_exe';
$res_data = $this->mf_exec($bin_exe . "\"". $res_data = $this->mf_exec($bin_exe,
"site_cd=" . $site_cd . "," . "site_cd=" . $site_cd . "," .
"site_key=" . $site_key . "," . "site_key=" . $site_key . "," .
"tx_cd=" . $tx_cd . "," . "tx_cd=" . $tx_cd . "," .
@@ -188,8 +189,7 @@
$ordr_data . $ordr_data .
$rcvr_data . $rcvr_data .
$escw_data . $escw_data .
$modx_data . $modx_data) ;
"\"") ;
} }
else else
{ {
@@ -276,21 +276,27 @@
return $my_data; return $my_data;
} }
function mf_exec() function mf_build_exec_cmd( $arg )
{ {
$arg = func_get_args();
if ( is_array( $arg[0] ) ) $arg = $arg[0]; if ( is_array( $arg[0] ) ) $arg = $arg[0];
$exec_cmd = array_shift( $arg ); $exec_cmd = array_shift( $arg );
foreach($arg as $i) foreach((array) $arg as $key=>$i)
{ {
$exec_cmd .= " " . escapeshellarg( $i ); $exec_cmd .= " " . escapeshellarg( $i );
} }
return $exec_cmd;
}
function mf_exec()
{
$arg = func_get_args();
$exec_cmd = $this->mf_build_exec_cmd( $arg );
$rt = exec( $exec_cmd ); $rt = exec( $exec_cmd );
return $rt; return $rt;
} }
} }
+1 -6
View File
@@ -11,11 +11,6 @@ if(defined('G5_THEME_MSHOP_PATH')) {
unset($theme_list_file); unset($theme_list_file);
} }
// 상품 리스트에서 다른 필드로 정렬을 하려면 아래의 배열 코드에서 해당 필드를 추가하세요.
if( isset($sort) && ! in_array($sort, array('it_name', 'it_sum_qty', 'it_price', 'it_use_avg', 'it_use_cnt', 'it_update_time')) ){
$sort='';
}
$sql = " select * $sql = " select *
from {$g5['g5_shop_category_table']} from {$g5['g5_shop_category_table']}
where ca_id = '$ca_id' where ca_id = '$ca_id'
@@ -200,4 +195,4 @@ var g5_shop_url = "<?php echo G5_SHOP_URL; ?>";
<?php <?php
include_once(G5_MSHOP_PATH.'/_tail.php'); include_once(G5_MSHOP_PATH.'/_tail.php');
echo "\n<!-- {$ca['ca_mobile_skin']} -->\n"; echo "\n<!-- {$ca['ca_mobile_skin']} -->\n";
+1 -4
View File
@@ -1,9 +1,6 @@
<?php <?php
include_once('./_common.php'); include_once('./_common.php');
// 상품 정렬 컬럼 화이트리스트 — 데스크톱 shop/listtype.php 와 동일 패턴
$sort = (isset($_REQUEST['sort']) && in_array($_REQUEST['sort'], array('it_name', 'it_sum_qty', 'it_price', 'it_use_avg', 'it_use_cnt', 'it_update_time'))) ? $_REQUEST['sort'] : '';
$type = isset($_REQUEST['type']) ? (int) preg_replace("/[^0-9]/", "", $_REQUEST['type']) : 1; $type = isset($_REQUEST['type']) ? (int) preg_replace("/[^0-9]/", "", $_REQUEST['type']) : 1;
if ($type === 1) $g5['title'] = '히트상품'; if ($type === 1) $g5['title'] = '히트상품';
else if ($type === 2) $g5['title'] = '추천상품'; else if ($type === 2) $g5['title'] = '추천상품';
@@ -78,4 +75,4 @@ echo get_paging($config['cf_mobile_pages'], $page, $total_page, "{$_SERVER['SCRI
?> ?>
<?php <?php
include_once(G5_MSHOP_PATH.'/_tail.php'); include_once(G5_MSHOP_PATH.'/_tail.php');
@@ -4,7 +4,7 @@ if (!defined("_GNUBOARD_")) exit; // 개별 페이지 접근 불가
<section id="bo_v_ans"> <section id="bo_v_ans">
<?php <?php
if($is_admin) // 관리자이면 답변등록 if($is_admin === 'super') // 최고관리자이면 답변등록
{ {
?> ?>
<h2>답변등록</h2> <h2>답변등록</h2>
@@ -151,4 +151,4 @@ if (!defined("_GNUBOARD_")) exit; // 개별 페이지 접근 불가
<?php <?php
} }
?> ?>
</section> </section>
+3 -3
View File
@@ -27,7 +27,7 @@ add_stylesheet('<link rel="stylesheet" href="'.G5_MSHOP_SKIN_URL.'/style.css">',
if($row['iq_secret']) { if($row['iq_secret']) {
$iq_subject .= ' <img src="'.G5_MSHOP_SKIN_URL.'/img/icon_secret.gif" alt="비밀글">'; $iq_subject .= ' <img src="'.G5_MSHOP_SKIN_URL.'/img/icon_secret.gif" alt="비밀글">';
if($is_admin || $member['mb_id' ] == $row['mb_id']) { if(is_shop_resource_owner_or_super_admin($row['mb_id'], $member['mb_id'], $is_admin)) {
$iq_question = get_view_thumbnail(conv_content($row['iq_question'], 1), $thumbnail_width); $iq_question = get_view_thumbnail(conv_content($row['iq_question'], 1), $thumbnail_width);
} else { } else {
$iq_question = '비밀글로 보호된 문의입니다.'; $iq_question = '비밀글로 보호된 문의입니다.';
@@ -87,7 +87,7 @@ add_stylesheet('<link rel="stylesheet" href="'.G5_MSHOP_SKIN_URL.'/style.css">',
<?php } ?> <?php } ?>
</div> </div>
<?php if ($is_admin || ($row['mb_id'] == $member['mb_id'] && !$is_answer)) { ?> <?php if ($is_admin === 'super' || ($row['mb_id'] == $member['mb_id'] && !$is_answer)) { ?>
<div class="sit_qa_cmd"> <div class="sit_qa_cmd">
<a href="<?php echo $itemqa_form."&amp;iq_id={$row['iq_id']}&amp;w=u"; ?>" class="itemqa_form btn01" onclick="return false;">수정</a> <a href="<?php echo $itemqa_form."&amp;iq_id={$row['iq_id']}&amp;w=u"; ?>" class="itemqa_form btn01" onclick="return false;">수정</a>
<a href="<?php echo $itemqa_formupdate."&amp;iq_id={$row['iq_id']}&amp;w=d&amp;hash={$hash}"; ?>" class="itemqa_delete btn01">삭제</a> <a href="<?php echo $itemqa_formupdate."&amp;iq_id={$row['iq_id']}&amp;w=d&amp;hash={$hash}"; ?>" class="itemqa_delete btn01">삭제</a>
@@ -148,4 +148,4 @@ $(function(){
}); });
}); });
</script> </script>
<!-- } 상품문의 목록 끝 --> <!-- } 상품문의 목록 끝 -->
+2 -2
View File
@@ -46,7 +46,7 @@ add_stylesheet('<link rel="stylesheet" href="'.G5_MSHOP_SKIN_URL.'/style.css">',
if($row['iq_secret']) { if($row['iq_secret']) {
$iq_subject .= ' <i class="fa fa-lock" aria-hidden="true"></i>'; $iq_subject .= ' <i class="fa fa-lock" aria-hidden="true"></i>';
if($is_admin || $member['mb_id' ] == $row['mb_id']) { if(is_shop_resource_owner_or_super_admin($row['mb_id'], $member['mb_id'], $is_admin)) {
$iq_question = get_view_thumbnail(conv_content($row['iq_question'], 1), $thumbnail_width); $iq_question = get_view_thumbnail(conv_content($row['iq_question'], 1), $thumbnail_width);
} else { } else {
$iq_question = '비밀글로 보호된 문의입니다.'; $iq_question = '비밀글로 보호된 문의입니다.';
@@ -141,4 +141,4 @@ $(function(){
}); });
}); });
</script> </script>
<!-- } 전체 상품 사용후기 목록 끝 --> <!-- } 전체 상품 사용후기 목록 끝 -->
+2 -2
View File
@@ -52,7 +52,7 @@ add_stylesheet('<link rel="stylesheet" href="'.G5_MSHOP_SKIN_URL.'/style.css">',
<?php echo $is_content; // 사용후기 내용 ?> <?php echo $is_content; // 사용후기 내용 ?>
</div> </div>
<?php if ($is_admin || $row['mb_id'] == $member['mb_id']) { ?> <?php if (is_shop_resource_owner_or_super_admin($row['mb_id'], $member['mb_id'], $is_admin)) { ?>
<div class="sit_use_cmd"> <div class="sit_use_cmd">
<a href="<?php echo $itemuse_form."&amp;is_id={$row['is_id']}&amp;w=u"; ?>" class="itemuse_form btn01" onclick="return false;">수정</a> <a href="<?php echo $itemuse_form."&amp;is_id={$row['is_id']}&amp;w=u"; ?>" class="itemuse_form btn01" onclick="return false;">수정</a>
<a href="<?php echo $itemuse_formupdate."&amp;is_id={$row['is_id']}&amp;w=d&amp;hash={$hash}"; ?>" class="itemuse_delete btn01">삭제</a> <a href="<?php echo $itemuse_formupdate."&amp;is_id={$row['is_id']}&amp;w=d&amp;hash={$hash}"; ?>" class="itemuse_delete btn01">삭제</a>
@@ -130,4 +130,4 @@ $(function(){
}); });
}); });
</script> </script>
<!-- } 상품 사용후기 끝 --> <!-- } 상품 사용후기 끝 -->
+8 -14
View File
@@ -1,22 +1,16 @@
<?php <?php
include_once('../common.php'); include_once('../common.php');
if (isset($_REQUEST['sort']) && !preg_match("/(--|#|\/\*|\*\/)/", $_REQUEST['sort'])) {
$sort = trim($_REQUEST['sort']);
$sort = preg_replace("/[\<\>\'\"\\\'\\\"\%\=\(\)\s]/", "", $sort);
} else {
$sort = '';
}
if (isset($_REQUEST['sortodr'])) {
$sortodr = preg_match("/^(asc|desc)$/i", $sortodr) ? $sortodr : '';
} else {
$sortodr = '';
}
if (!defined('G5_USE_SHOP') || !G5_USE_SHOP) if (!defined('G5_USE_SHOP') || !G5_USE_SHOP)
die('<p>쇼핑몰 설치 후 이용해 주십시오.</p>'); die('<p>쇼핑몰 설치 후 이용해 주십시오.</p>');
$is_admin = get_super_admin_type($is_admin);
$request_sort = (isset($_REQUEST['sort']) && is_string($_REQUEST['sort'])) ? $_REQUEST['sort'] : '';
$request_sortodr = (isset($_REQUEST['sortodr']) && is_string($_REQUEST['sortodr'])) ? $_REQUEST['sortodr'] : '';
list($sort, $sortodr) = get_shop_item_sort($request_sort, $request_sortodr);
unset($request_sort, $request_sortodr);
define('_SHOP_', true); define('_SHOP_', true);
define('_SHOP_COMMON_', true); // 모바일 페이지의 직접 접근을 막는 경우에 사용 define('_SHOP_COMMON_', true); // 모바일 페이지의 직접 접근을 막는 경우에 사용
?> ?>
+1 -6
View File
@@ -5,11 +5,6 @@ $ev_id = isset($_GET['ev_id']) ? (int) $_GET['ev_id'] : 0;
$skin = isset($_GET['skin']) ? clean_xss_tags($_GET['skin'], 1, 1) : ''; $skin = isset($_GET['skin']) ? clean_xss_tags($_GET['skin'], 1, 1) : '';
$ca_id = isset($_GET['ca_id']) ? clean_xss_tags($_GET['ca_id'], 1, 1) : ''; $ca_id = isset($_GET['ca_id']) ? clean_xss_tags($_GET['ca_id'], 1, 1) : '';
// 상품 리스트에서 다른 필드로 정렬을 하려면 아래의 배열 코드에서 해당 필드를 추가하세요.
if( isset($sort) && ! in_array($sort, array('it_name', 'it_sum_qty', 'it_price', 'it_use_avg', 'it_use_cnt', 'it_update_time')) ){
$sort='';
}
if (G5_IS_MOBILE) { if (G5_IS_MOBILE) {
include_once(G5_MSHOP_PATH.'/event.php'); include_once(G5_MSHOP_PATH.'/event.php');
return; return;
@@ -117,4 +112,4 @@ if (file_exists($timg))
<!-- } 이벤트 끝 --> <!-- } 이벤트 끝 -->
<?php <?php
include_once('./_tail.php'); include_once('./_tail.php');
+2 -2
View File
@@ -38,7 +38,7 @@ if ($w == "u")
$it_id = $qa['it_id']; $it_id = $qa['it_id'];
if (!$is_admin && $qa['mb_id'] != $member['mb_id']) { if (!is_shop_resource_owner_or_super_admin($qa['mb_id'], $member['mb_id'], $is_admin)) {
alert_close("자신의 상품문의만 수정이 가능합니다."); alert_close("자신의 상품문의만 수정이 가능합니다.");
} }
@@ -66,4 +66,4 @@ if(!file_exists($itemqaform_skin)) {
include_once($itemqaform_skin); include_once($itemqaform_skin);
} }
include_once(G5_PATH.'/tail.sub.php'); include_once(G5_PATH.'/tail.sub.php');
+2 -2
View File
@@ -37,7 +37,7 @@ if ($w == "") {
$it_id = $use['it_id']; $it_id = $use['it_id'];
$is_score = $use['is_score']; $is_score = $use['is_score'];
if (!$is_admin && $use['mb_id'] != $member['mb_id']) { if (!is_shop_resource_owner_or_super_admin($use['mb_id'], $member['mb_id'], $is_admin)) {
alert_close("자신의 사용후기만 수정이 가능합니다."); alert_close("자신의 사용후기만 수정이 가능합니다.");
} }
} }
@@ -62,4 +62,4 @@ if(!file_exists($itemuseform_skin)) {
include_once($itemuseform_skin); include_once($itemuseform_skin);
} }
include_once(G5_PATH.'/tail.sub.php'); include_once(G5_PATH.'/tail.sub.php');
+11 -5
View File
@@ -168,7 +168,7 @@
{ {
if (strtoupper(substr(PHP_OS, 0, 3)) === 'WIN') if (strtoupper(substr(PHP_OS, 0, 3)) === 'WIN')
{ {
// 실행 파일 경로와 인자를 분리하여 mf_exec 호출 → escapeshellarg 자동 적용 (KVE-2026-0859) // 실행 파일 경로와 인자를 분리하여 mf_exec 호출 → escapeshellarg 자동 적용
$bin_exe = $home_dir.'/bin/pp_cli_exe'; $bin_exe = $home_dir.'/bin/pp_cli_exe';
$res_data = $this->mf_exec($bin_exe, $res_data = $this->mf_exec($bin_exe,
@@ -276,10 +276,8 @@
return $my_data; return $my_data;
} }
function mf_exec() function mf_build_exec_cmd( $arg )
{ {
$arg = func_get_args();
if ( is_array( $arg[0] ) ) $arg = $arg[0]; if ( is_array( $arg[0] ) ) $arg = $arg[0];
$exec_cmd = array_shift( $arg ); $exec_cmd = array_shift( $arg );
@@ -289,8 +287,16 @@
$exec_cmd .= " " . escapeshellarg( $i ); $exec_cmd .= " " . escapeshellarg( $i );
} }
return $exec_cmd;
}
function mf_exec()
{
$arg = func_get_args();
$exec_cmd = $this->mf_build_exec_cmd( $arg );
$rt = exec( $exec_cmd ); $rt = exec( $exec_cmd );
return $rt; return $rt;
} }
} }
+1 -9
View File
@@ -4,14 +4,6 @@ include_once('./_common.php');
$ca_id = isset($_REQUEST['ca_id']) ? safe_replace_regex($_REQUEST['ca_id'], 'ca_id') : ''; $ca_id = isset($_REQUEST['ca_id']) ? safe_replace_regex($_REQUEST['ca_id'], 'ca_id') : '';
$skin = isset($_REQUEST['skin']) ? safe_replace_regex($_REQUEST['skin'], 'skin') : ''; $skin = isset($_REQUEST['skin']) ? safe_replace_regex($_REQUEST['skin'], 'skin') : '';
// 상품 리스트에서 다른 필드로 정렬을 하려면 아래의 배열 코드에서 해당 필드를 추가하세요.
if( isset($sort) && ! in_array($sort, array('it_name', 'it_sum_qty', 'it_price', 'it_use_avg', 'it_use_cnt', 'it_update_time')) ){
$sort='';
}
if( !isset($sortodr) || !in_array(strtolower($sortodr), array('asc', 'desc')) ){
$sortodr='';
}
if (G5_IS_MOBILE) { if (G5_IS_MOBILE) {
include_once(G5_MSHOP_PATH.'/list.php'); include_once(G5_MSHOP_PATH.'/list.php');
return; return;
@@ -181,4 +173,4 @@ if ($ca['ca_include_tail'] && is_include_path_check($ca['ca_include_tail'])
else else
include_once(G5_SHOP_PATH.'/_tail.php'); include_once(G5_SHOP_PATH.'/_tail.php');
echo "\n<!-- {$ca['ca_skin']} -->\n"; echo "\n<!-- {$ca['ca_skin']} -->\n";
+1 -3
View File
@@ -1,8 +1,6 @@
<?php <?php
include_once('./_common.php'); include_once('./_common.php');
// 상품 리스트에서 다른 필드로 정렬을 하려면 아래의 배열 코드에서 해당 필드를 추가하세요.
$sort = (isset($_REQUEST['sort']) && in_array($_REQUEST['sort'], array('it_name', 'it_sum_qty', 'it_price', 'it_use_avg', 'it_use_cnt', 'it_update_time'))) ? $_REQUEST['sort'] : '';
$type = isset($_REQUEST['type']) ? (int) preg_replace("/[^0-9]/", "", $_REQUEST['type']) : 1; $type = isset($_REQUEST['type']) ? (int) preg_replace("/[^0-9]/", "", $_REQUEST['type']) : 1;
if (G5_IS_MOBILE) { if (G5_IS_MOBILE) {
@@ -83,4 +81,4 @@ else
$qstr .= '&amp;type='.$type.'&amp;sort='.$sort; $qstr .= '&amp;type='.$type.'&amp;sort='.$sort;
echo get_paging($config['cf_write_pages'], $page, $total_page, "{$_SERVER['SCRIPT_NAME']}?$qstr&amp;page="); echo get_paging($config['cf_write_pages'], $page, $total_page, "{$_SERVER['SCRIPT_NAME']}?$qstr&amp;page=");
include_once('./_tail.php'); include_once('./_tail.php');
+2 -2
View File
@@ -4,7 +4,7 @@ if (!defined("_GNUBOARD_")) exit; // 개별 페이지 접근 불가
<section id="bo_v_ans_form"> <section id="bo_v_ans_form">
<?php <?php
if($is_admin) // 관리자이면 답변등록 if($is_admin === 'super') // 최고관리자이면 답변등록
{ {
?> ?>
<h2>답변등록</h2> <h2>답변등록</h2>
@@ -152,4 +152,4 @@ if (!defined("_GNUBOARD_")) exit; // 개별 페이지 접근 불가
<?php <?php
} }
?> ?>
</section> </section>
+3 -3
View File
@@ -29,7 +29,7 @@ add_stylesheet('<link rel="stylesheet" href="'.G5_SHOP_SKIN_URL.'/style.css">',
if($row['iq_secret']) { if($row['iq_secret']) {
$iq_subject .= ' <img src="'.G5_SHOP_SKIN_URL.'/img/icon_secret.gif" alt="비밀글">'; $iq_subject .= ' <img src="'.G5_SHOP_SKIN_URL.'/img/icon_secret.gif" alt="비밀글">';
if($is_admin || $member['mb_id' ] == $row['mb_id']) { if(is_shop_resource_owner_or_super_admin($row['mb_id'], $member['mb_id'], $is_admin)) {
$iq_question = get_view_thumbnail(conv_content($row['iq_question'], 1), $thumbnail_width); $iq_question = get_view_thumbnail(conv_content($row['iq_question'], 1), $thumbnail_width);
} else { } else {
$iq_question = '비밀글로 보호된 문의입니다.'; $iq_question = '비밀글로 보호된 문의입니다.';
@@ -85,7 +85,7 @@ add_stylesheet('<link rel="stylesheet" href="'.G5_SHOP_SKIN_URL.'/style.css">',
<?php } ?> <?php } ?>
</div> </div>
<?php if ($is_admin || ($row['mb_id'] == $member['mb_id'] && !$is_answer)) { ?> <?php if ($is_admin === 'super' || ($row['mb_id'] == $member['mb_id'] && !$is_answer)) { ?>
<div class="sit_qa_cmd"> <div class="sit_qa_cmd">
<a href="<?php echo $itemqa_form."&amp;iq_id={$row['iq_id']}&amp;w=u"; ?>" class="itemqa_form btn01" onclick="return false;">수정</a> <a href="<?php echo $itemqa_form."&amp;iq_id={$row['iq_id']}&amp;w=u"; ?>" class="itemqa_form btn01" onclick="return false;">수정</a>
<a href="<?php echo $itemqa_formupdate."&amp;iq_id={$row['iq_id']}&amp;w=d&amp;hash={$hash}"; ?>" class="itemqa_delete btn01">삭제</a> <a href="<?php echo $itemqa_formupdate."&amp;iq_id={$row['iq_id']}&amp;w=d&amp;hash={$hash}"; ?>" class="itemqa_delete btn01">삭제</a>
@@ -140,4 +140,4 @@ $(function(){
}); });
}); });
</script> </script>
<!-- } 상품문의 목록 끝 --> <!-- } 상품문의 목록 끝 -->
+2 -2
View File
@@ -44,7 +44,7 @@ add_stylesheet('<link rel="stylesheet" href="'.G5_SHOP_SKIN_URL.'/style.css">',
if($row['iq_secret']) { if($row['iq_secret']) {
$iq_subject .= ' <i class="fa fa-lock" aria-hidden="true"></i>'; $iq_subject .= ' <i class="fa fa-lock" aria-hidden="true"></i>';
if($is_admin || $member['mb_id' ] == $row['mb_id']) { if(is_shop_resource_owner_or_super_admin($row['mb_id'], $member['mb_id'], $is_admin)) {
$iq_question = get_view_thumbnail(conv_content($row['iq_question'], 1), $thumbnail_width); $iq_question = get_view_thumbnail(conv_content($row['iq_question'], 1), $thumbnail_width);
} else { } else {
$iq_question = '비밀글로 보호된 문의입니다.'; $iq_question = '비밀글로 보호된 문의입니다.';
@@ -141,4 +141,4 @@ $(function(){
}); });
}); });
</script> </script>
<!-- } 전체 상품 사용후기 목록 끝 --> <!-- } 전체 상품 사용후기 목록 끝 -->
+2 -2
View File
@@ -59,7 +59,7 @@ add_stylesheet('<link rel="stylesheet" href="'.G5_SHOP_SKIN_URL.'/style.css">',
<?php echo $is_content; // 사용후기 내용 ?> <?php echo $is_content; // 사용후기 내용 ?>
</div> </div>
<?php if ($is_admin || $row['mb_id'] == $member['mb_id']) { ?> <?php if (is_shop_resource_owner_or_super_admin($row['mb_id'], $member['mb_id'], $is_admin)) { ?>
<div class="sit_use_cmd"> <div class="sit_use_cmd">
<a href="<?php echo $itemuse_form."&amp;is_id={$row['is_id']}&amp;w=u"; ?>" class="itemuse_form btn01" onclick="return false;">수정</a> <a href="<?php echo $itemuse_form."&amp;is_id={$row['is_id']}&amp;w=u"; ?>" class="itemuse_form btn01" onclick="return false;">수정</a>
<a href="<?php echo $itemuse_formupdate."&amp;is_id={$row['is_id']}&amp;w=d&amp;hash={$hash}"; ?>" class="itemuse_delete btn01">삭제</a> <a href="<?php echo $itemuse_formupdate."&amp;is_id={$row['is_id']}&amp;w=d&amp;hash={$hash}"; ?>" class="itemuse_delete btn01">삭제</a>
@@ -131,4 +131,4 @@ $(function(){
}); });
}); });
</script> </script>
<!-- } 상품 사용후기 끝 --> <!-- } 상품 사용후기 끝 -->
@@ -4,7 +4,7 @@ if (!defined("_GNUBOARD_")) exit; // 개별 페이지 접근 불가
<section id="bo_v_ans"> <section id="bo_v_ans">
<?php <?php
if($is_admin) // 관리자이면 답변등록 if($is_admin === 'super') // 최고관리자이면 답변등록
{ {
?> ?>
<h2>답변등록</h2> <h2>답변등록</h2>
@@ -151,4 +151,4 @@ if (!defined("_GNUBOARD_")) exit; // 개별 페이지 접근 불가
<?php <?php
} }
?> ?>
</section> </section>
@@ -27,7 +27,7 @@ add_stylesheet('<link rel="stylesheet" href="'.G5_MSHOP_SKIN_URL.'/style.css">',
if($row['iq_secret']) { if($row['iq_secret']) {
$iq_subject .= ' <img src="'.G5_MSHOP_SKIN_URL.'/img/icon_secret.gif" alt="비밀글">'; $iq_subject .= ' <img src="'.G5_MSHOP_SKIN_URL.'/img/icon_secret.gif" alt="비밀글">';
if($is_admin || $member['mb_id' ] == $row['mb_id']) { if(is_shop_resource_owner_or_super_admin($row['mb_id'], $member['mb_id'], $is_admin)) {
$iq_question = get_view_thumbnail(conv_content($row['iq_question'], 1), $thumbnail_width); $iq_question = get_view_thumbnail(conv_content($row['iq_question'], 1), $thumbnail_width);
} else { } else {
$iq_question = '비밀글로 보호된 문의입니다.'; $iq_question = '비밀글로 보호된 문의입니다.';
@@ -87,7 +87,7 @@ add_stylesheet('<link rel="stylesheet" href="'.G5_MSHOP_SKIN_URL.'/style.css">',
<?php } ?> <?php } ?>
</div> </div>
<?php if ($is_admin || ($row['mb_id'] == $member['mb_id'] && !$is_answer)) { ?> <?php if ($is_admin === 'super' || ($row['mb_id'] == $member['mb_id'] && !$is_answer)) { ?>
<div class="sit_qa_cmd"> <div class="sit_qa_cmd">
<a href="<?php echo $itemqa_form."&amp;iq_id={$row['iq_id']}&amp;w=u"; ?>" class="itemqa_form btn01" onclick="return false;">수정</a> <a href="<?php echo $itemqa_form."&amp;iq_id={$row['iq_id']}&amp;w=u"; ?>" class="itemqa_form btn01" onclick="return false;">수정</a>
<a href="<?php echo $itemqa_formupdate."&amp;iq_id={$row['iq_id']}&amp;w=d&amp;hash={$hash}"; ?>" class="itemqa_delete btn01">삭제</a> <a href="<?php echo $itemqa_formupdate."&amp;iq_id={$row['iq_id']}&amp;w=d&amp;hash={$hash}"; ?>" class="itemqa_delete btn01">삭제</a>
@@ -148,4 +148,4 @@ $(function(){
}); });
}); });
</script> </script>
<!-- } 상품문의 목록 끝 --> <!-- } 상품문의 목록 끝 -->
@@ -46,7 +46,7 @@ add_stylesheet('<link rel="stylesheet" href="'.G5_MSHOP_SKIN_URL.'/style.css">',
if($row['iq_secret']) { if($row['iq_secret']) {
$iq_subject .= ' <i class="fa fa-lock" aria-hidden="true"></i>'; $iq_subject .= ' <i class="fa fa-lock" aria-hidden="true"></i>';
if($is_admin || $member['mb_id' ] == $row['mb_id']) { if(is_shop_resource_owner_or_super_admin($row['mb_id'], $member['mb_id'], $is_admin)) {
$iq_question = get_view_thumbnail(conv_content($row['iq_question'], 1), $thumbnail_width); $iq_question = get_view_thumbnail(conv_content($row['iq_question'], 1), $thumbnail_width);
} else { } else {
$iq_question = '비밀글로 보호된 문의입니다.'; $iq_question = '비밀글로 보호된 문의입니다.';
@@ -141,4 +141,4 @@ $(function(){
}); });
}); });
</script> </script>
<!-- } 전체 상품 사용후기 목록 끝 --> <!-- } 전체 상품 사용후기 목록 끝 -->
@@ -52,7 +52,7 @@ add_stylesheet('<link rel="stylesheet" href="'.G5_MSHOP_SKIN_URL.'/style.css">',
<?php echo $is_content; // 사용후기 내용 ?> <?php echo $is_content; // 사용후기 내용 ?>
</div> </div>
<?php if ($is_admin || $row['mb_id'] == $member['mb_id']) { ?> <?php if (is_shop_resource_owner_or_super_admin($row['mb_id'], $member['mb_id'], $is_admin)) { ?>
<div class="sit_use_cmd"> <div class="sit_use_cmd">
<a href="<?php echo $itemuse_form."&amp;is_id={$row['is_id']}&amp;w=u"; ?>" class="itemuse_form btn01" onclick="return false;">수정</a> <a href="<?php echo $itemuse_form."&amp;is_id={$row['is_id']}&amp;w=u"; ?>" class="itemuse_form btn01" onclick="return false;">수정</a>
<a href="<?php echo $itemuse_formupdate."&amp;is_id={$row['is_id']}&amp;w=d&amp;hash={$hash}"; ?>" class="itemuse_delete btn01">삭제</a> <a href="<?php echo $itemuse_formupdate."&amp;is_id={$row['is_id']}&amp;w=d&amp;hash={$hash}"; ?>" class="itemuse_delete btn01">삭제</a>
@@ -130,4 +130,4 @@ $(function(){
}); });
}); });
</script> </script>
<!-- } 상품 사용후기 끝 --> <!-- } 상품 사용후기 끝 -->
+8 -14
View File
@@ -1,20 +1,14 @@
<?php <?php
include_once('../../../common.php'); include_once('../../../common.php');
if (isset($_REQUEST['sort']) && !preg_match("/(--|#|\/\*|\*\/)/", $_REQUEST['sort'])) {
$sort = trim($_REQUEST['sort']);
$sort = preg_replace("/[\<\>\'\"\\\'\\\"\%\=\(\)\s]/", "", $sort);
} else {
$sort = '';
}
if (isset($_REQUEST['sortodr'])) {
$sortodr = preg_match("/^(asc|desc)$/i", $sortodr) ? $sortodr : '';
} else {
$sortodr = '';
}
if (!defined('G5_USE_SHOP') || !G5_USE_SHOP) if (!defined('G5_USE_SHOP') || !G5_USE_SHOP)
die('<p>쇼핑몰 설치 후 이용해 주십시오.</p>'); die('<p>쇼핑몰 설치 후 이용해 주십시오.</p>');
define('_SHOP_', true); $is_admin = get_super_admin_type($is_admin);
$request_sort = (isset($_REQUEST['sort']) && is_string($_REQUEST['sort'])) ? $_REQUEST['sort'] : '';
$request_sortodr = (isset($_REQUEST['sortodr']) && is_string($_REQUEST['sortodr'])) ? $_REQUEST['sortodr'] : '';
list($sort, $sortodr) = get_shop_item_sort($request_sort, $request_sortodr);
unset($request_sort, $request_sortodr);
define('_SHOP_', true);
@@ -4,7 +4,7 @@ if (!defined("_GNUBOARD_")) exit; // 개별 페이지 접근 불가
<section id="bo_v_ans_form"> <section id="bo_v_ans_form">
<?php <?php
if($is_admin) // 관리자이면 답변등록 if($is_admin === 'super') // 최고관리자이면 답변등록
{ {
?> ?>
<h2>답변등록</h2> <h2>답변등록</h2>
@@ -152,4 +152,4 @@ if (!defined("_GNUBOARD_")) exit; // 개별 페이지 접근 불가
<?php <?php
} }
?> ?>
</section> </section>
+3 -3
View File
@@ -29,7 +29,7 @@ add_stylesheet('<link rel="stylesheet" href="'.G5_SHOP_SKIN_URL.'/style.css">',
if($row['iq_secret']) { if($row['iq_secret']) {
$iq_subject .= ' <img src="'.G5_SHOP_SKIN_URL.'/img/icon_secret.gif" alt="비밀글">'; $iq_subject .= ' <img src="'.G5_SHOP_SKIN_URL.'/img/icon_secret.gif" alt="비밀글">';
if($is_admin || $member['mb_id' ] == $row['mb_id']) { if(is_shop_resource_owner_or_super_admin($row['mb_id'], $member['mb_id'], $is_admin)) {
$iq_question = get_view_thumbnail(conv_content($row['iq_question'], 1), $thumbnail_width); $iq_question = get_view_thumbnail(conv_content($row['iq_question'], 1), $thumbnail_width);
} else { } else {
$iq_question = '비밀글로 보호된 문의입니다.'; $iq_question = '비밀글로 보호된 문의입니다.';
@@ -85,7 +85,7 @@ add_stylesheet('<link rel="stylesheet" href="'.G5_SHOP_SKIN_URL.'/style.css">',
<?php } ?> <?php } ?>
</div> </div>
<?php if ($is_admin || ($row['mb_id'] == $member['mb_id'] && !$is_answer)) { ?> <?php if ($is_admin === 'super' || ($row['mb_id'] == $member['mb_id'] && !$is_answer)) { ?>
<div class="sit_qa_cmd"> <div class="sit_qa_cmd">
<a href="<?php echo $itemqa_form."&amp;iq_id={$row['iq_id']}&amp;w=u"; ?>" class="itemqa_form btn01" onclick="return false;">수정</a> <a href="<?php echo $itemqa_form."&amp;iq_id={$row['iq_id']}&amp;w=u"; ?>" class="itemqa_form btn01" onclick="return false;">수정</a>
<a href="<?php echo $itemqa_formupdate."&amp;iq_id={$row['iq_id']}&amp;w=d&amp;hash={$hash}"; ?>" class="itemqa_delete btn01">삭제</a> <a href="<?php echo $itemqa_formupdate."&amp;iq_id={$row['iq_id']}&amp;w=d&amp;hash={$hash}"; ?>" class="itemqa_delete btn01">삭제</a>
@@ -140,4 +140,4 @@ $(function(){
}); });
}); });
</script> </script>
<!-- } 상품문의 목록 끝 --> <!-- } 상품문의 목록 끝 -->
@@ -44,7 +44,7 @@ add_stylesheet('<link rel="stylesheet" href="'.G5_SHOP_SKIN_URL.'/style.css">',
if($row['iq_secret']) { if($row['iq_secret']) {
$iq_subject .= ' <i class="fa fa-lock" aria-hidden="true"></i>'; $iq_subject .= ' <i class="fa fa-lock" aria-hidden="true"></i>';
if($is_admin || $member['mb_id' ] == $row['mb_id']) { if(is_shop_resource_owner_or_super_admin($row['mb_id'], $member['mb_id'], $is_admin)) {
$iq_question = get_view_thumbnail(conv_content($row['iq_question'], 1), $thumbnail_width); $iq_question = get_view_thumbnail(conv_content($row['iq_question'], 1), $thumbnail_width);
} else { } else {
$iq_question = '비밀글로 보호된 문의입니다.'; $iq_question = '비밀글로 보호된 문의입니다.';
@@ -141,4 +141,4 @@ $(function(){
}); });
}); });
</script> </script>
<!-- } 전체 상품 사용후기 목록 끝 --> <!-- } 전체 상품 사용후기 목록 끝 -->
+2 -2
View File
@@ -59,7 +59,7 @@ add_stylesheet('<link rel="stylesheet" href="'.G5_SHOP_SKIN_URL.'/style.css">',
<?php echo $is_content; // 사용후기 내용 ?> <?php echo $is_content; // 사용후기 내용 ?>
</div> </div>
<?php if ($is_admin || $row['mb_id'] == $member['mb_id']) { ?> <?php if (is_shop_resource_owner_or_super_admin($row['mb_id'], $member['mb_id'], $is_admin)) { ?>
<div class="sit_use_cmd"> <div class="sit_use_cmd">
<a href="<?php echo $itemuse_form."&amp;is_id={$row['is_id']}&amp;w=u"; ?>" class="itemuse_form btn01" onclick="return false;">수정</a> <a href="<?php echo $itemuse_form."&amp;is_id={$row['is_id']}&amp;w=u"; ?>" class="itemuse_form btn01" onclick="return false;">수정</a>
<a href="<?php echo $itemuse_formupdate."&amp;is_id={$row['is_id']}&amp;w=d&amp;hash={$hash}"; ?>" class="itemuse_delete btn01">삭제</a> <a href="<?php echo $itemuse_formupdate."&amp;is_id={$row['is_id']}&amp;w=d&amp;hash={$hash}"; ?>" class="itemuse_delete btn01">삭제</a>
@@ -131,4 +131,4 @@ $(function(){
}); });
}); });
</script> </script>
<!-- } 상품 사용후기 끝 --> <!-- } 상품 사용후기 끝 -->