From bf75dc1d97178ad6ad4f557317866a2b20e32582 Mon Sep 17 00:00:00 2001 From: thisgun Date: Wed, 13 Mar 2019 09:37:48 +0900 Subject: [PATCH] =?UTF-8?q?KVE-2019-0567,=200657=20XSS=20=EC=B7=A8?= =?UTF-8?q?=EC=95=BD=EC=A0=90=20=EC=88=98=EC=A0=95?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- mobile/shop/event.php | 2 ++ shop/event.php | 2 ++ shop/orderform.php | 2 ++ 3 files changed, 6 insertions(+) diff --git a/mobile/shop/event.php b/mobile/shop/event.php index d690164b6..74dfd2836 100644 --- a/mobile/shop/event.php +++ b/mobile/shop/event.php @@ -1,6 +1,8 @@ ', 0); +$sw_direct = preg_replace('/[^a-z0-9_]/i', '', $sw_direct); + // 모바일 주문인지 $is_mobile_order = is_mobile();