Files
Gnuboard5/shop/itemuselist.php
thisgunandClaude Opus 4.7 6b2f9e094c [security] ORDER BY sst/sod 화이트리스트 누락 Blind SQL Injection 수정
KVE-2026-0876 동일 패턴 추가 발견 5건 일괄 수정.

- shop/itemuselist.php / mobile/shop/itemuselist.php (상품후기 목록)
- shop/itemqalist.php / mobile/shop/itemqalist.php (상품문의 목록)
  → 비회원 접근 가능한 공개 페이지에서 sst/sod 가 ORDER BY 절에
    검증 없이 삽입되어 CASE WHEN/SLEEP 기반 blind SQLi 가능했음.
    sst 는 컬럼 화이트리스트, sod 는 asc/desc 정규식으로 검증.

- bbs/list.php (게시판 목록)
  → sst 는 wr_datetime/wr_hit/wr_good/wr_nogood 화이트리스트 적용
    되어 있으나 sod 가 검증 누락되어 ORDER BY 절에 함수 표현식
    삽입이 가능했음. sod 에 asc/desc 정규식 검증 추가.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 06:32:28 +00:00

76 lines
2.2 KiB
PHP

<?php
include_once('./_common.php');
if( isset($sfl) && ! in_array($sfl, array('b.it_name', 'a.it_id', 'a.is_subject', 'a.is_content', 'a.is_name', 'a.mb_id')) ){
//다른값이 들어가있다면 초기화
$sfl = '';
}
if (G5_IS_MOBILE) {
include_once(G5_MSHOP_PATH.'/itemuselist.php');
return;
}
$g5['title'] = '사용후기';
include_once('./_head.php');
$sql_common = " from `{$g5['g5_shop_item_use_table']}` a join `{$g5['g5_shop_item_table']}` b on (a.it_id=b.it_id) ";
$sql_search = " where a.is_confirm = '1' ";
if(!$sfl)
$sfl = 'b.it_name';
if ($stx) {
$sql_search .= " and ( ";
switch ($sfl) {
case "a.it_id" :
$sql_search .= " ($sfl like '$stx%') ";
break;
case "a.is_name" :
case "a.mb_id" :
$sql_search .= " ($sfl = '$stx') ";
break;
default :
$sql_search .= " ($sfl like '%$stx%') ";
break;
}
$sql_search .= " ) ";
}
if (!$sst) {
$sst = "a.is_id";
$sod = "desc";
}
// 정렬 컬럼/방향 화이트리스트
$sst = in_array($sst, array('a.is_id', 'a.is_datetime', 'a.is_score', 'a.it_id', 'b.it_name'), true) ? $sst : 'a.is_id';
$sod = preg_match("/^(asc|desc)$/i", $sod) ? $sod : 'desc';
$sql_order = " order by $sst $sod ";
$sql = " select count(*) as cnt
$sql_common
$sql_search
$sql_order ";
$row = sql_fetch($sql);
$total_count = $row['cnt'];
$rows = $config['cf_page_rows'];
$total_page = ceil($total_count / $rows); // 전체 페이지 계산
if ($page < 1) { $page = 1; } // 페이지가 없으면 첫 페이지 (1 페이지)
$from_record = ($page - 1) * $rows; // 시작 열을 구함
$sql = " select *
$sql_common
$sql_search
$sql_order
limit $from_record, $rows ";
$result = sql_query($sql);
$itemuselist_skin = G5_SHOP_SKIN_PATH.'/itemuselist.skin.php';
if(!file_exists($itemuselist_skin)) {
echo str_replace(G5_PATH.'/', '', $itemuselist_skin).' 스킨 파일이 존재하지 않습니다.';
} else {
include_once($itemuselist_skin);
}
include_once('./_tail.php');