게시판·1:1문의·쇼핑몰분류 상단/하단 파일 경로 처리 보강

콘텐츠와 동일하게, 게시판(bo_include)·1:1문의(qa_include)·쇼핑몰 분류
(ca_include)의 상단/하단 파일 경로도 저장 전에 먼저 정규화한 뒤 확장자와
위치를 검증하도록 순서를 조정한다. 정규화 과정에서 확장자가 사라져 검증을
우회하던 경로를 차단하고, data 디렉터리로 귀결되는 경로를 거부한다.

실행 직전 board_head/board_tail, qahead/qatail, shop 목록·상품 페이지에서도
승인 확장자와 data 디렉터리 여부를 다시 확인하는 is_content_include_allowed()
를 적용한다. 이미 저장된 경로도 실행 시 재확인된다.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 0c6bca704725ebea2a584d4c06366282e9bc36d6)
This commit is contained in:
thisgun
2026-08-24 07:44:22 +00:00
parent 6571119db6
commit 96df43480b
9 changed files with 53 additions and 19 deletions
+4 -2
View File
@@ -107,7 +107,8 @@ define('G5_SHOP_CSS_URL', str_replace(G5_PATH, G5_URL, $skin_dir));
$g5['title'] = $it['it_name'].' &gt; '.$it['ca_name'];
// 분류 상단 코드가 있으면 출력하고 없으면 기본 상단 코드 출력
if ($ca['ca_include_head'] && is_include_path_check($ca['ca_include_head']))
if ($ca['ca_include_head'] && is_include_path_check($ca['ca_include_head'])
&& (!function_exists('is_content_include_allowed') || is_content_include_allowed($ca['ca_include_head'])))
@include_once($ca['ca_include_head']);
else
include_once(G5_SHOP_PATH.'/_head.php');
@@ -280,7 +281,8 @@ echo run_replace('shop_it_tail_html', conv_content($it['it_tail_html'], 1), $it)
?>
<?php
if ($ca['ca_include_tail'] && is_include_path_check($ca['ca_include_tail']))
if ($ca['ca_include_tail'] && is_include_path_check($ca['ca_include_tail'])
&& (!function_exists('is_content_include_allowed') || is_content_include_allowed($ca['ca_include_tail'])))
@include_once($ca['ca_include_tail']);
else
include_once(G5_SHOP_PATH.'/_tail.php');
+4 -2
View File
@@ -50,7 +50,8 @@ if(!$is_admin && $config['cf_cert_use']) {
$g5['title'] = $ca['ca_name'].' 상품리스트';
if ($ca['ca_include_head'] && is_include_path_check($ca['ca_include_head']))
if ($ca['ca_include_head'] && is_include_path_check($ca['ca_include_head'])
&& (!function_exists('is_content_include_allowed') || is_content_include_allowed($ca['ca_include_head'])))
@include_once($ca['ca_include_head']);
else
include_once(G5_SHOP_PATH.'/_head.php');
@@ -174,7 +175,8 @@ var itemlist_ca_id = "<?php echo $ca_id; ?>";
<!-- } 상품 목록 끝 -->
<?php
if ($ca['ca_include_tail'] && is_include_path_check($ca['ca_include_tail']))
if ($ca['ca_include_tail'] && is_include_path_check($ca['ca_include_tail'])
&& (!function_exists('is_content_include_allowed') || is_content_include_allowed($ca['ca_include_tail'])))
@include_once($ca['ca_include_tail']);
else
include_once(G5_SHOP_PATH.'/_tail.php');