diff --git a/bbs/move_update.php b/bbs/move_update.php index 6d7e5cee0..0977a299b 100644 --- a/bbs/move_update.php +++ b/bbs/move_update.php @@ -21,11 +21,11 @@ $cnt = 0; // SQL Injection 으로 인한 코드 보완 //$sql = " select distinct wr_num from {$write_table} where wr_id in (" . stripslashes($wr_id_list) . ") order by wr_id "; -$sql = " select distinct wr_num from {$write_table} where wr_id in ({$wr_id_list}) order by wr_id "; +$sql = " select distinct wr_num from $write_table where wr_id in ({$wr_id_list}) order by wr_id "; $result = sql_query($sql); while ($row = sql_fetch_array($result)) { - $wr_num = $row[wr_num]; + $wr_num = $row['wr_num']; for ($i=0; $i