KVE-2026-0876 동일 패턴 추가 발견 5건 일괄 수정.
- shop/itemuselist.php / mobile/shop/itemuselist.php (상품후기 목록)
- shop/itemqalist.php / mobile/shop/itemqalist.php (상품문의 목록)
→ 비회원 접근 가능한 공개 페이지에서 sst/sod 가 ORDER BY 절에
검증 없이 삽입되어 CASE WHEN/SLEEP 기반 blind SQLi 가능했음.
sst 는 컬럼 화이트리스트, sod 는 asc/desc 정규식으로 검증.
- bbs/list.php (게시판 목록)
→ sst 는 wr_datetime/wr_hit/wr_good/wr_nogood 화이트리스트 적용
되어 있으나 sod 가 검증 누락되어 ORDER BY 절에 함수 표현식
삽입이 가능했음. sod 에 asc/desc 정규식 검증 추가.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
76 lines
2.2 KiB
PHP
76 lines
2.2 KiB
PHP
<?php
|
|
include_once('./_common.php');
|
|
|
|
if( isset($sfl) && ! in_array($sfl, array('b.it_name', 'a.it_id', 'a.is_subject', 'a.is_content', 'a.is_name', 'a.mb_id')) ){
|
|
//다른값이 들어가있다면 초기화
|
|
$sfl = '';
|
|
}
|
|
|
|
if (G5_IS_MOBILE) {
|
|
include_once(G5_MSHOP_PATH.'/itemuselist.php');
|
|
return;
|
|
}
|
|
|
|
$g5['title'] = '사용후기';
|
|
include_once('./_head.php');
|
|
|
|
$sql_common = " from `{$g5['g5_shop_item_use_table']}` a join `{$g5['g5_shop_item_table']}` b on (a.it_id=b.it_id) ";
|
|
$sql_search = " where a.is_confirm = '1' ";
|
|
|
|
if(!$sfl)
|
|
$sfl = 'b.it_name';
|
|
|
|
if ($stx) {
|
|
$sql_search .= " and ( ";
|
|
switch ($sfl) {
|
|
case "a.it_id" :
|
|
$sql_search .= " ($sfl like '$stx%') ";
|
|
break;
|
|
case "a.is_name" :
|
|
case "a.mb_id" :
|
|
$sql_search .= " ($sfl = '$stx') ";
|
|
break;
|
|
default :
|
|
$sql_search .= " ($sfl like '%$stx%') ";
|
|
break;
|
|
}
|
|
$sql_search .= " ) ";
|
|
}
|
|
|
|
if (!$sst) {
|
|
$sst = "a.is_id";
|
|
$sod = "desc";
|
|
}
|
|
// 정렬 컬럼/방향 화이트리스트
|
|
$sst = in_array($sst, array('a.is_id', 'a.is_datetime', 'a.is_score', 'a.it_id', 'b.it_name'), true) ? $sst : 'a.is_id';
|
|
$sod = preg_match("/^(asc|desc)$/i", $sod) ? $sod : 'desc';
|
|
$sql_order = " order by $sst $sod ";
|
|
|
|
$sql = " select count(*) as cnt
|
|
$sql_common
|
|
$sql_search
|
|
$sql_order ";
|
|
$row = sql_fetch($sql);
|
|
$total_count = $row['cnt'];
|
|
|
|
$rows = $config['cf_page_rows'];
|
|
$total_page = ceil($total_count / $rows); // 전체 페이지 계산
|
|
if ($page < 1) { $page = 1; } // 페이지가 없으면 첫 페이지 (1 페이지)
|
|
$from_record = ($page - 1) * $rows; // 시작 열을 구함
|
|
|
|
$sql = " select *
|
|
$sql_common
|
|
$sql_search
|
|
$sql_order
|
|
limit $from_record, $rows ";
|
|
$result = sql_query($sql);
|
|
|
|
$itemuselist_skin = G5_SHOP_SKIN_PATH.'/itemuselist.skin.php';
|
|
|
|
if(!file_exists($itemuselist_skin)) {
|
|
echo str_replace(G5_PATH.'/', '', $itemuselist_skin).' 스킨 파일이 존재하지 않습니다.';
|
|
} else {
|
|
include_once($itemuselist_skin);
|
|
}
|
|
|
|
include_once('./_tail.php'); |