diff --git a/adm/shop_admin/inorderlistdelete.php b/adm/shop_admin/inorderlistdelete.php index 1f718672d..a4b75cef1 100644 --- a/adm/shop_admin/inorderlistdelete.php +++ b/adm/shop_admin/inorderlistdelete.php @@ -6,7 +6,7 @@ check_demo(); auth_check($auth[$sub_menu], 'd'); -check_token(); +check_admin_token(); $count = count($_POST['chk']); if(!$count) diff --git a/adm/shop_admin/itemeventlist.php b/adm/shop_admin/itemeventlist.php index 099a4a67f..7568b0cf9 100644 --- a/adm/shop_admin/itemeventlist.php +++ b/adm/shop_admin/itemeventlist.php @@ -6,6 +6,7 @@ auth_check($auth[$sub_menu], "r"); $ev_id = preg_replace('/[^0-9]/', '', $ev_id); $sort1 = strip_tags($sort1); +if (!in_array($sort1, array('a.it_id', 'it_name'))) $sort1 = "a.it_id"; $sel_field = strip_tags($sel_field); $sel_ca_id = get_search_string($sel_ca_id); $search = get_search_string($search); diff --git a/adm/shop_admin/itemsellrank.php b/adm/shop_admin/itemsellrank.php index 858ed4d9d..7de79c8aa 100644 --- a/adm/shop_admin/itemsellrank.php +++ b/adm/shop_admin/itemsellrank.php @@ -11,6 +11,7 @@ include_once(G5_PLUGIN_PATH.'/jquery-ui/datepicker.php'); if (!$to_date) $to_date = date("Ymd", time()); if ($sort1 == "") $sort1 = "ct_status_sum"; +if (!in_array($sort1, array('ct_status_1', 'ct_status_2', 'ct_status_3', 'ct_status_4', 'ct_status_5', 'ct_status_6', 'ct_status_7', 'ct_status_8', 'ct_status_9', 'ct_status_sum'))) $sort1 = "ct_status_sum"; if ($sort2 == "" || $sort2 != "asc") $sort2 = "desc"; $doc = strip_tags($doc); diff --git a/adm/shop_admin/itemstocksms.php b/adm/shop_admin/itemstocksms.php index 9e567b76e..8a0dc6539 100644 --- a/adm/shop_admin/itemstocksms.php +++ b/adm/shop_admin/itemstocksms.php @@ -33,6 +33,7 @@ if ($search != "") { if ($sel_field == "") $sel_field = "it_it"; if ($sort1 == "") $sort1 = "ss_send"; +if (!in_array($sort1, array('it_id', 'ss_hp', 'ss_send', 'ss_send_time', 'ss_datetime'))) $sort1 = "ss_send"; if ($sort2 == "" || $sort2 != "desc") $sort2 = "asc"; $doc = strip_tags($doc); diff --git a/adm/shop_admin/itemstocksmsupdate.php b/adm/shop_admin/itemstocksmsupdate.php index 624766de5..f78ce5358 100644 --- a/adm/shop_admin/itemstocksmsupdate.php +++ b/adm/shop_admin/itemstocksmsupdate.php @@ -102,8 +102,6 @@ if ($_POST['act_button'] == "선택SMS전송") { auth_check($auth[$sub_menu], 'd'); - check_token(); - for ($i=0; $i