게시판 정렬 필드 화이트리스트 검증 추가

게시판 설정의 bo_sort_field 가 허용 목록 검증 없이 저장·사용되어
목록 조회 ORDER BY 절에 임의 표현식이 들어갈 수 있던 문제 수정.
정렬값은 따옴표로 감싸지 않아 escape 로 막히지 않으므로,
게시판 관리 권한 계정이 저장한 값이 비로그인 목록 조회에서
실행될 수 있었음.

get_board_sort_fields() 의 허용 목록(관리자 드롭다운과 동일)으로
저장(adm/board_form_update.php)과 사용(bbs/list.php) 양쪽을 검증.
허용 목록 외 값은 기본 정렬로 무력화하여 이미 저장된 값도 차단.
function_exists 가드로 부분 패치 환경 대비.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
thisgun
2026-06-05 07:20:58 +00:00
co-authored by Claude Opus 4.8
parent afd8b35423
commit 76d83c2bae
2 changed files with 18 additions and 2 deletions
+11 -1
View File
@@ -176,7 +176,17 @@ $bo_write_min = isset($_POST['bo_write_min']) ? (int) $_POST['bo_write_min'] : 0
$bo_write_max = isset($_POST['bo_write_max']) ? (int) $_POST['bo_write_max'] : 0;
$bo_comment_min = isset($_POST['bo_comment_min']) ? (int) $_POST['bo_comment_min'] : 0;
$bo_comment_max = isset($_POST['bo_comment_max']) ? (int) $_POST['bo_comment_max'] : 0;
$bo_sort_field = isset($_POST['bo_sort_field']) ? addslashes(clean_xss_tags(stripslashes($_POST['bo_sort_field']), 1, 1)) : '';
$bo_sort_field = isset($_POST['bo_sort_field']) ? trim(stripslashes($_POST['bo_sort_field'])) : '';
$bo_allowed_sort_field = array('');
if (function_exists('get_board_sort_fields')) {
foreach (get_board_sort_fields(isset($board) ? $board : array()) as $bo_sort_v) {
$bo_allowed_sort_field[] = $bo_sort_v[0];
}
}
if (!in_array($bo_sort_field, $bo_allowed_sort_field, true)) {
$bo_sort_field = '';
}
$bo_sort_field = addslashes($bo_sort_field);
if (strpbrk($bo_skin.$bo_mobile_skin, "?%*:|\"<>") !== false) {
alert('스킨 디렉토리명 오류!');
+7 -1
View File
@@ -170,7 +170,13 @@ $td_width = (int)(100 / $bo_gallery_cols);
// 인덱스 필드가 아니면 정렬에 사용하지 않음
//if (!$sst || ($sst && !(strstr($sst, 'wr_id') || strstr($sst, "wr_datetime")))) {
if (!$sst) {
if ($board['bo_sort_field']) {
$bo_allowed_sort_field = array();
if (function_exists('get_board_sort_fields')) {
foreach (get_board_sort_fields($board) as $bo_sort_v) {
$bo_allowed_sort_field[] = $bo_sort_v[0];
}
}
if ($board['bo_sort_field'] && in_array($board['bo_sort_field'], $bo_allowed_sort_field, true)) {
$sst = $board['bo_sort_field'];
} else {
$sst = "wr_num, wr_reply";