From 752ccd8502161654ffba10598d7ed25fd3baa11b Mon Sep 17 00:00:00 2001 From: chicpro Date: Mon, 10 Feb 2014 10:52:58 +0900 Subject: [PATCH] =?UTF-8?q?member=5Fconfirm=20=ED=8C=8C=EC=9D=BC=20url=20?= =?UTF-8?q?=EB=A6=AC=EB=8B=A4=EC=9D=B4=EB=A0=89=EC=85=98=20=EC=B7=A8?= =?UTF-8?q?=EC=95=BD=EC=A0=90=20=EC=88=98=EC=A0=95=20-=20=EA=B9=80?= =?UTF-8?q?=ED=9A=A8=EC=A2=85=EB=8B=98=20=EB=B3=B4=EA=B3=A0?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- bbs/member_confirm.php | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/bbs/member_confirm.php b/bbs/member_confirm.php index bdacb1d9b..d55c6d14a 100644 --- a/bbs/member_confirm.php +++ b/bbs/member_confirm.php @@ -14,6 +14,15 @@ else $g5['title'] = '회원 비밀번호 확인'; include_once('./_head.sub.php'); +$url = $_GET['url']; + +$p = parse_url($url); +if ((isset($p['scheme']) && $p['scheme']) || (isset($p['host']) && $p['host'])) { + //print_r2($p); + if ($p['host'].(isset($p['port']) ? ':'.$p['port'] : '') != $_SERVER['HTTP_HOST']) + alert('url에 타 도메인을 지정할 수 없습니다.'); +} + include_once($member_skin_path.'/member_confirm.skin.php'); include_once('./_tail.sub.php');