From 9823909cfdea5d16244a94b9dc37ea40ac2143a7 Mon Sep 17 00:00:00 2001 From: chicpro Date: Wed, 9 Jul 2014 10:12:06 +0900 Subject: [PATCH] =?UTF-8?q?escape=20=ED=8C=A8=ED=84=B4=EC=9D=B4=20?= =?UTF-8?q?=EC=A0=95=EC=9D=98=EB=90=98=EC=96=B4=20=EC=9E=88=EC=9D=84=20?= =?UTF-8?q?=EA=B2=BD=EC=9A=B0=EC=97=90=EB=A7=8C=20=EC=A0=81=EC=9A=A9?= =?UTF-8?q?=EB=90=98=EB=8F=84=EB=A1=9D=20=EC=BD=94=EB=93=9C=20=EC=88=98?= =?UTF-8?q?=EC=A0=95?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- common.php | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/common.php b/common.php index 91a930548..4a6a4d37d 100644 --- a/common.php +++ b/common.php @@ -68,10 +68,14 @@ function array_map_deep($fn, $array) // SQL Injection 대응 문자열 필터링 function sql_escape_string($str) { - $pattern = G5_ESCAPE_PATTERN; - $replace = G5_ESCAPE_REPLACE; + if(defined('G5_ESCAPE_PATTERN') && defined('G5_ESCAPE_REPLACE')) { + $pattern = G5_ESCAPE_PATTERN; + $replace = G5_ESCAPE_REPLACE; + + if($pattern) + $str = preg_replace($pattern, $replace, $str); + } - $str = preg_replace($pattern, $replace, $str); $str = call_user_func('addslashes', $str); return $str;