Reflected XSS 취약점(16-036) 수정

This commit is contained in:
chicpro
2016-01-20 16:23:38 +09:00
parent f3abd57925
commit 714d64afb6

View File

@ -33,6 +33,8 @@ $msg2 = str_replace("\\n", "<br>", $msg);
$url = clean_xss_tags($url);
if (!$url) $url = clean_xss_tags($_SERVER['HTTP_REFERER']);
$url = preg_replace("/[\<\>\'\"\\\'\\\"\(\)]/", "", $url);
// url 체크
check_url_host($url);