thisgun
f2e7dbc5ed
[security]그누보드5 XSS, SQL Injection 취약점 수정
2026-04-16 03:46:02 +00:00
thisgun
79f915988b
[security]개인결제 hash 검증을 strict 비교(===)로 강화
...
shop/personalpayformupdate.php와 lib/shop.lib.php의 ss_personalpay_hash
검증이 loose 비교(==/!=)를 사용하여 PHP type juggling 잠재적 우회 가능성이
있었음. md5 결과 중 "0e..." 형식 hash는 PHP의 loose 비교에서 0e 지수
표기법으로 해석되어 다른 "0e..." 해시와 동등 판정될 수 있음
(소위 magic hash collision 패턴).
실제 익스플로잇 가능성은 낮지만 (md5 출력은 32자 hex 문자열이고 PHP의
문자열 vs 문자열 비교에서는 0e... 패턴이 적용되지 않는 경우가 많음),
defense in depth 차원에서 strict 비교로 변경.
mobile/shop/personalpayformupdate.php는 이미 strict 비교를 사용 중이라
core 두 곳만 동일한 패턴으로 정렬.
- shop/personalpayformupdate.php:35: != / != → !== / !==
- lib/shop.lib.php:2333: == → ===
2026-04-16 02:46:49 +00:00
thisgun
3cfe8b6b84
[security]현금영수증 발급 페이지 IDOR 취약점 수정
2026-04-16 02:43:22 +00:00
thisgun
a612e69d3e
[perf]for 루프 조건의 count() 호출을 루프 밖으로 추출 (핵심 파일)
...
for ($i=0; $i<count(\$arr); $i++) 패턴은 매 반복마다 count()를 호출하여
불필요한 CPU 오버헤드를 발생시킴. 루프 전에 한 번만 count()를 계산하여
변수에 저장하는 고전적인 최적화.
적용 파일 (19개, 41곳):
- lib/common.lib.php (8)
- common.php (2)
- lib/shop.lib.php (5)
- lib/naverpay.lib.php (1)
- lib/thumbnail.lib.php (2)
- bbs/list.php (1), bbs/search.php (4), bbs/qalist.php (1), bbs/qawrite.php (1)
- bbs/ajax.filter.php (1), bbs/write_update.php (4)
- bbs/write_comment_update.php (1), bbs/memo_form_update.php (2)
- bbs/new_delete.php (1), bbs/move_update.php (4)
- shop/search.php (1), shop/orderform.sub.php (1)
- mobile/shop/search.php (1), mobile/shop/orderform.sub.php (1)
부수 효과:
- lib/shop.lib.php line 2115: 동일 루프 내 strstr($dlcomp, $company)를
strpos($dlcomp, $company) !== false 로 변경 (strstr 최적화의 일부)
제외:
- theme/, skin/, plugin/ (사용자 커스터마이징/서드파티)
- lib/PHPExcel/ (서드파티 라이브러리)
- adm/ 및 shop/mail/ (관리자/드문 경로, 별도 후속 작업 여지)
- 주석 처리된 코드 (bbs/delete.php:127, bbs/delete_all.php:143)
2026-04-16 02:26:59 +00:00
thisgun
c00c73465a
[security]비회원 주문/개인결제 조회 uid를 HMAC-SHA256으로 강화
2026-04-16 02:15:29 +00:00
thisgun
3e0e8be6da
[security]쇼핑몰 update 엔드포인트 CSRF 보호 추가
2026-04-16 02:02:26 +00:00
thisgun
b3fa6dc127
[KVE-2026-0595]영카트5 SQL Injection 취약점 수정
2026-04-06 06:26:20 +00:00
thisgun
604cef808e
[보안패치]그누보드 영카트 SQL_injection 취약점 수정
2026-03-31 01:21:11 +00:00
thisgun
c3db9b454e
[KVE-2026-0569]그누보드,영카트 SQL Injection 취약점 수정
2026-03-30 11:50:30 +00:00
thisgun
bf19cd8bf5
[KVE-2026-0568]영카트 SQL Injection 취약점 수정
2026-03-30 11:03:16 +00:00
thisgun
b2c0e1af29
[KVE-2026-0554]그누보드,영카트 SQL Injection 취약점 수정
2026-03-30 09:52:41 +00:00
thisgun
5054e24631
[KVE-2026-0243]영카트주문시_쿠폰중복사용취약점_수정
2026-03-25 09:18:48 +00:00
thisgun
5e6b4fa668
[KVE-2026-0242]영카트주문취소시_포인트복구취약점_수정
2026-03-25 04:59:56 +00:00
thisgun
0ddcda4b0c
toss 모바일결제 포인트 적용시 결제 오류 수정
2026-02-02 09:37:49 +00:00
thisgun
607e15424d
토스결제 비회원결제가 안되는 오류 및 모바일 개인결제 취소과정 코드 수정
2026-02-02 07:18:28 +00:00
thisgun
0e06b4f9ce
영카트5에서 사용자가 현금영수증 발급버튼이 출력되지 않는 오류 수정
2026-01-26 09:33:19 +00:00
thisgun
f2ab751e5f
[KVE-2025-0828]영카트 취약점 수정
2025-11-14 07:30:47 +00:00
thisgun
1438f8d557
충돌수정
2025-09-22 10:39:44 +09:00
chym1217
7e8eff5395
팝빌 알림톡 제거 완료
...
- 광고성 및 회원관리파일(친구톡 코드만 제거) 제외
2025-09-19 17:53:50 +09:00
chym1217
f4718a71a2
feat: 관리자페이지 토스페이먼츠 명칭 변경 및 테스트결제 안내 추가
...
- 기존 : 토스페이먼츠 -> 토스페이먼츠(구버전)
- 토스페이먼츠 V2 -> 토스페이먼츠 API
- 기타 css 및 주석 수정
2025-09-17 10:44:40 +09:00
chym1217
46ea2d03b5
토스페이먼츠 v2 결제 모듈 연동
2025-09-16 16:34:15 +09:00
chym1217
66f6a75a10
팝빌 알림톡 기능 추가
2025-09-04 12:37:12 +09:00
thisgun
9758007f91
NHN_KCP 네이버페이 간편결제 카드 또는 머니결제로 분리
2025-07-31 20:21:22 +09:00
restarea92 and GitHub
327e7ba7ba
feat: add list.php theme override ( #358 )
...
* feat: add theme override in shop/list.php
* feat: add theme override in mobile/shop/list.php
2025-06-27 09:35:52 +09:00
thisgun
aa88ff68a1
KG이니시스 IDC 센터코드 검증 추가2
2025-06-12 17:34:53 +09:00
thisgun
bb1f69e86c
KG이니시스 IDC 센터코드 검증 추가
2025-06-05 16:11:20 +09:00
thisgun
c1bbce1114
KG이니시스 가상계좌 에스크로 IP 추가
2025-05-28 11:27:59 +09:00
thisgun
ea9f618de8
KG이니시스 모바일 가상계좌 IP 추가
2025-05-15 15:29:26 +09:00
thisgun
316d3542a9
[KVE-2025-0259]XSS 취약점 수정
2025-05-15 09:53:28 +09:00
thisgun
69180914f8
쇼핑몰 가상계좌 정보(toss)에 은행이름이 하나 더 붙은 문제 수정
2025-02-04 11:01:41 +09:00
thisgun
3ca77a38fb
위시리스트에서 주문하기시 상품이 잘못 장바구니 담기되는 오류 수정
2024-10-23 15:23:47 +09:00
thisgun
20eb993757
나이스페이 주문정보 입력 오류시 결제 취소 코드 추가 및 불필요한 코드 제거
2024-09-04 12:55:05 +09:00
thisgun
3474be175d
토스페이먼츠 (구)lg XPay 테스트 에스크로 배송 url 수정
2024-09-03 18:03:21 +09:00
thisgun
532bf6f0f4
토스페이먼츠 (구)lg XPay 도메인 지원종료에 따른 결제도메인 수정
2024-09-03 17:17:55 +09:00
thisgun
92c1052cf5
NHN_KCP 결제정보 검증기능 추가 적용
2024-05-14 17:10:00 +09:00
thisgun
c4763a64d8
쇼핑몰 주문 SMS 파일의 금액변수에 (int) 형 추가
2024-05-14 16:04:14 +09:00
thisgun
6048a8a1c5
NHN_KCP 결제정보 검증기능 적용
2024-04-17 15:21:55 +09:00
thisgun
84669cb47f
나이스페이 결제수단 추가
2024-04-03 10:42:04 +09:00
thisgun
2bfd995e49
쇼핑몰 결제시 결세수단 체크 과정 추가
2024-04-03 09:59:02 +09:00
thisgun
a0eb804918
[KVE-2024-0023] 답변이 달린 상품문의글 수정가능 취약점 수정
2024-03-25 10:47:29 +09:00
thisgun
0d9c773d22
[KVE-2024-0022] 쇼핑몰 사용후기 별점 조작 취약점 수정
2024-03-25 10:03:07 +09:00
thisgun
248cb2b173
관리자 페이지 원격 명령 실행 취약점 수정
2024-02-14 19:09:20 +09:00
thisgun
73a5f4cc47
NHN_KCP 에스크로 마크 상점코드가 SIR로 나왔던 오류 수정
2024-01-24 10:53:16 +09:00
thisgun
a061d6c863
동시성 문제로 wr_seo_title 값이 중복되는 문제 수정 #293
2023-12-18 17:26:30 +09:00
maycactus
3a7d06b19e
Fix array element and string offset access using square brackets
...
In accordance with the PHP RFC deprecating the curly brace syntax for accessing array elements and string offsets, this commit replaces all instances of {} with [].
By making this change, we ensure the codebase remains compliant with the recommended syntax, enhancing code readability and maintainability. The deprecation of curly brace syntax was done to align with best practices and promote a consistent code style.
2023-07-25 13:34:00 -04:00
thisgun
6eaa6ee22a
Merge branch 'master' of github.com:gnuboard/gnuboard5
2023-07-17 11:54:08 +09:00
thisgun
ec3fdce5c7
장바구니 업데이트시 sum_qty변수 형변환 수정
2023-07-11 10:41:33 +09:00
thisgun
79ce9ec984
6월 25일 제보한 영카트 보안취약점 수정 #249
2023-07-11 10:33:39 +09:00
thisgun
ffc8706a76
[KVE-2023-5153] XSS 취약점 수정
2023-07-04 18:37:23 +09:00
kkigomi
bbbc568db8
관리자 페이지 및 일부 데이터 업데이트 시 Event hook 추가
2023-06-25 03:49:10 +09:00