회원 홈페이지를 이용한 SQL Injection 오류 수정
This commit is contained in:
@ -407,9 +407,9 @@ if ($w == '' || $w == 'r') {
|
||||
// 자신의 글이라면
|
||||
if ($member['mb_id'] == $wr['mb_id']) {
|
||||
$mb_id = $member['mb_id'];
|
||||
$wr_name = $board['bo_use_name'] ? $member['mb_name'] : $member['mb_nick'];
|
||||
$wr_email = $member['mb_email'];
|
||||
$wr_homepage = $member['mb_homepage'];
|
||||
$wr_name = addslashes(clean_xss_tags($board['bo_use_name'] ? $member['mb_name'] : $member['mb_nick']));
|
||||
$wr_email = addslashes($member['mb_email']);
|
||||
$wr_homepage = addslashes(clean_xss_tags($member['mb_homepage']));
|
||||
} else {
|
||||
$mb_id = $wr['mb_id'];
|
||||
$wr_name = $wr['wr_name'];
|
||||
|
||||
Reference in New Issue
Block a user