그누보드 XSS 취약점(KVE-2019-1235,1236,1238)

This commit is contained in:
thisgun
2019-08-29 12:23:29 +09:00
parent 120d42c431
commit c2922aaa13
2 changed files with 2 additions and 2 deletions

View File

@ -306,7 +306,7 @@ if(!isset($qaconfig['qa_include_head'])) {
<tr>
<th scope="row"><label for="qa_insert_content">글쓰기 기본 내용</label></th>
<td>
<textarea id="qa_insert_content" name="qa_insert_content" rows="5"><?php echo $qaconfig['qa_insert_content'] ?></textarea>
<textarea id="qa_insert_content" name="qa_insert_content" rows="5"><?php echo html_purifier($qaconfig['qa_insert_content']); ?></textarea>
</td>
</tr>
<?php for ($i=1; $i<=5; $i++) { ?>

View File

@ -67,7 +67,7 @@ if(is_file($skin_file)) {
$content = '';
if ($w == '') {
$content = $qaconfig['qa_insert_content'];
$content = html_purifier($qaconfig['qa_insert_content']);
} else if($w == 'r') {
if($is_dhtml_editor)
$content = '<div><br><br><br>====== 이전 답변내용 =======<br></div>';