게시판 정렬 필드 화이트리스트 검증 추가
게시판 설정의 bo_sort_field 가 허용 목록 검증 없이 저장·사용되어 목록 조회 ORDER BY 절에 임의 표현식이 들어갈 수 있던 문제 수정. 정렬값은 따옴표로 감싸지 않아 escape 로 막히지 않으므로, 게시판 관리 권한 계정이 저장한 값이 비로그인 목록 조회에서 실행될 수 있었음. get_board_sort_fields() 의 허용 목록(관리자 드롭다운과 동일)으로 저장(adm/board_form_update.php)과 사용(bbs/list.php) 양쪽을 검증. 허용 목록 외 값은 기본 정렬로 무력화하여 이미 저장된 값도 차단. function_exists 가드로 부분 패치 환경 대비. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
afd8b35423
commit
76d83c2bae
@@ -176,7 +176,17 @@ $bo_write_min = isset($_POST['bo_write_min']) ? (int) $_POST['bo_write_min'] : 0
|
||||
$bo_write_max = isset($_POST['bo_write_max']) ? (int) $_POST['bo_write_max'] : 0;
|
||||
$bo_comment_min = isset($_POST['bo_comment_min']) ? (int) $_POST['bo_comment_min'] : 0;
|
||||
$bo_comment_max = isset($_POST['bo_comment_max']) ? (int) $_POST['bo_comment_max'] : 0;
|
||||
$bo_sort_field = isset($_POST['bo_sort_field']) ? addslashes(clean_xss_tags(stripslashes($_POST['bo_sort_field']), 1, 1)) : '';
|
||||
$bo_sort_field = isset($_POST['bo_sort_field']) ? trim(stripslashes($_POST['bo_sort_field'])) : '';
|
||||
$bo_allowed_sort_field = array('');
|
||||
if (function_exists('get_board_sort_fields')) {
|
||||
foreach (get_board_sort_fields(isset($board) ? $board : array()) as $bo_sort_v) {
|
||||
$bo_allowed_sort_field[] = $bo_sort_v[0];
|
||||
}
|
||||
}
|
||||
if (!in_array($bo_sort_field, $bo_allowed_sort_field, true)) {
|
||||
$bo_sort_field = '';
|
||||
}
|
||||
$bo_sort_field = addslashes($bo_sort_field);
|
||||
|
||||
if (strpbrk($bo_skin.$bo_mobile_skin, "?%*:|\"<>") !== false) {
|
||||
alert('스킨 디렉토리명 오류!');
|
||||
|
||||
+7
-1
@@ -170,7 +170,13 @@ $td_width = (int)(100 / $bo_gallery_cols);
|
||||
// 인덱스 필드가 아니면 정렬에 사용하지 않음
|
||||
//if (!$sst || ($sst && !(strstr($sst, 'wr_id') || strstr($sst, "wr_datetime")))) {
|
||||
if (!$sst) {
|
||||
if ($board['bo_sort_field']) {
|
||||
$bo_allowed_sort_field = array();
|
||||
if (function_exists('get_board_sort_fields')) {
|
||||
foreach (get_board_sort_fields($board) as $bo_sort_v) {
|
||||
$bo_allowed_sort_field[] = $bo_sort_v[0];
|
||||
}
|
||||
}
|
||||
if ($board['bo_sort_field'] && in_array($board['bo_sort_field'], $bo_allowed_sort_field, true)) {
|
||||
$sst = $board['bo_sort_field'];
|
||||
} else {
|
||||
$sst = "wr_num, wr_reply";
|
||||
|
||||
Reference in New Issue
Block a user