취약점 [KVE-18-339] 수정

This commit is contained in:
thisgun
2018-07-03 15:29:06 +09:00
parent 12ad5e9cb5
commit c6f28c120c
4 changed files with 10 additions and 4 deletions

View File

@ -5,7 +5,13 @@ include_once('./_common.php');
auth_check($auth[$sub_menu], "r");
$g5['title'] = 'FAQ 상세관리';
if ($fm_subject) $g5['title'] .= ' : '.$fm_subject;
if ($fm_subject){
$fm_subject = clean_xss_tags(strip_tags($fm_subject));
$g5['title'] .= ' : '.$fm_subject;
}
$fm_id = (int) $fm_id;
include_once (G5_ADMIN_PATH.'/admin.head.php');
$sql = " select * from {$g5['faq_master_table']} where fm_id = '$fm_id' ";