diff --git a/.gitignore b/.gitignore
index 78e439322..309e1c111 100644
--- a/.gitignore
+++ b/.gitignore
@@ -14,3 +14,4 @@ log/
g5_tree/
naver*.html
initests01/
+SIRsoft000/
diff --git a/adm/member_form.php b/adm/member_form.php
index e47771fcd..ddcdfbe47 100644
--- a/adm/member_form.php
+++ b/adm/member_form.php
@@ -214,11 +214,9 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
| 받으시는 분 주소 |
-
-
- -
-
-
-
+
+
+
diff --git a/adm/shop_admin/orderformupdate.php b/adm/shop_admin/orderformupdate.php
index fc425c3c1..1ff37a11c 100644
--- a/adm/shop_admin/orderformupdate.php
+++ b/adm/shop_admin/orderformupdate.php
@@ -3,6 +3,11 @@ $sub_menu = '400400';
include_once('./_common.php');
if($_POST['mod_type'] == 'info') {
+ $od_zip1 = substr($_POST['od_zip'], 0, 3);
+ $od_zip2 = substr($_POST['od_zip'], 3);
+ $od_b_zip1 = substr($_POST['od_b_zip'], 0, 3);
+ $od_b_zip2 = substr($_POST['od_b_zip'], 3);
+
$sql = " update {$g5['g5_shop_order_table']}
set od_name = '$od_name',
od_tel = '$od_tel',
diff --git a/adm/shop_admin/orderprintresult.php b/adm/shop_admin/orderprintresult.php
index 2120f3bfd..461e9f111 100644
--- a/adm/shop_admin/orderprintresult.php
+++ b/adm/shop_admin/orderprintresult.php
@@ -104,7 +104,7 @@ if ($csv == 'csv')
$ct_send_cost = iconv_euckr($ct_send_cost);
}
- echo '"'.$row['od_b_zip1'].'-'.$row['od_b_zip2'].'"'.',';
+ echo '"'.$row['od_b_zip1'].$row['od_b_zip2'].'"'.',';
echo '"'.print_address($row['od_b_addr1'], $row['od_b_addr2'], $row['od_b_addr3'], $row['od_b_addr_jibeon']).'"'.',';
echo '"'.$row['od_b_name'].'"'.',';
//echo '"'.multibyte_digit((string)$row[od_b_tel]).'"'.',';
@@ -209,7 +209,7 @@ if ($csv == 'xls')
$row = array_map('iconv_euckr', $row);
- $worksheet->write($i, 0, $row['od_b_zip1'].'-'.$row['od_b_zip2']);
+ $worksheet->write($i, 0, $row['od_b_zip1'].$row['od_b_zip2']);
$worksheet->write($i, 1, print_address($row['od_b_addr1'], $row['od_b_addr2'], $row['od_b_addr3'], $row['od_b_addr_jibeon']));
$worksheet->write($i, 2, $row['od_b_name']);
$worksheet->write($i, 3, ' '.$row['od_b_tel']);
@@ -291,8 +291,8 @@ if (mysql_num_rows($result) == 0)
$row1 = sql_fetch($sql1);
// 1.03.02
- $row1['od_addr'] = '('.$row1['od_zip1'].'-'.$row1['od_zip2'].') '.print_address($row1['od_addr1'], $row1['od_addr2'], $row1['od_addr3'], $row1['od_addr_jibeon']);
- $row1['od_b_addr'] = '('.$row1['od_b_zip1'].'-'.$row1['od_b_zip2'].') '.print_address($row1['od_b_addr1'], $row1['od_b_addr2'], $row1['od_b_addr3'], $row1['od_b_addr_jibeon']);
+ $row1['od_addr'] = '('.$row1['od_zip1'].$row1['od_zip2'].') '.print_address($row1['od_addr1'], $row1['od_addr2'], $row1['od_addr3'], $row1['od_addr_jibeon']);
+ $row1['od_b_addr'] = '('.$row1['od_b_zip1'].$row1['od_b_zip2'].') '.print_address($row1['od_b_addr1'], $row1['od_b_addr2'], $row1['od_b_addr3'], $row1['od_b_addr_jibeon']);
$row1['od_addr'] = ($row1['od_addr']) ? $row1['od_addr'] : '입력안함';
$row1['od_tel'] = ($row1['od_tel']) ? $row1['od_tel'] : '입력안함';
diff --git a/adm/sms_admin/history_send.php b/adm/sms_admin/history_send.php
index a28d981fe..214815a6a 100644
--- a/adm/sms_admin/history_send.php
+++ b/adm/sms_admin/history_send.php
@@ -116,7 +116,7 @@ if ($result)
$row['bk_hp'] = get_hp($row['bk_hp'], 1);
$log = array_shift($SMS->Log);
- $log = @iconv('UTF-8', 'UTF-8//IGNORE', $log);
+ $log = @iconv('euc-kr', 'utf-8', $log);
sql_query("insert into {$g5['sms5_history_table']} set wr_no='$wr_no', wr_renum='$new_wr_renum', bg_no='{$row['bg_no']}', mb_id='{$row['mb_id']}', bk_no='{$row['bk_no']}', hs_name='{$row['hs_name']}', hs_hp='{$row['hs_hp']}', hs_datetime='".G5_TIME_YMDHIS."', hs_flag='$hs_flag', hs_code='$hs_code', hs_memo='".addslashes($hs_memo)."', hs_log='".addslashes($log)."'", false);
}
diff --git a/adm/sms_admin/sms_write_send.php b/adm/sms_admin/sms_write_send.php
index 45646ffec..5bbc285bb 100644
--- a/adm/sms_admin/sms_write_send.php
+++ b/adm/sms_admin/sms_write_send.php
@@ -202,7 +202,7 @@ if ($result)
$row['bk_hp'] = get_hp($row['bk_hp'], 1);
$log = array_shift($SMS->Log);
- $log = @iconv('UTF-8', 'UTF-8//IGNORE', $log);
+ $log = @iconv('euc-kr', 'utf-8', $log);
sql_query("insert into {$g5['sms5_history_table']} set wr_no='$wr_no', wr_renum=0, bg_no='{$row['bg_no']}', mb_id='{$row['mb_id']}', bk_no='{$row['bk_no']}', hs_name='".addslashes($row['bk_name'])."', hs_hp='{$row['bk_hp']}', hs_datetime='".G5_TIME_YMDHIS."', hs_flag='$hs_flag', hs_code='$hs_code', hs_memo='".addslashes($hs_memo)."', hs_log='".addslashes($log)."'", false);
}
diff --git a/bbs/alert.php b/bbs/alert.php
index d64b6f2fd..6b1ab26a7 100644
--- a/bbs/alert.php
+++ b/bbs/alert.php
@@ -30,7 +30,8 @@ include_once(G5_PATH.'/head.sub.php');
$msg2 = str_replace("\\n", " ", $msg);
-if (!$url) $url = $_SERVER['HTTP_REFERER'];
+$url = clean_xss_tags($url);
+if (!$url) $url = clean_xss_tags($_SERVER['HTTP_REFERER']);
// url 체크
check_url_host($url);
diff --git a/bbs/confirm.php b/bbs/confirm.php
index 76e9c7652..fcf94e0e9 100644
--- a/bbs/confirm.php
+++ b/bbs/confirm.php
@@ -2,6 +2,10 @@
include_once('./_common.php');
include_once(G5_PATH.'/head.sub.php');
+$url1 = clean_xss_tags($url1);
+$url2 = clean_xss_tags($url2);
+$url3 = clean_xss_tags($url3);
+
// url 체크
check_url_host($url1);
check_url_host($url2);
diff --git a/bbs/move.php b/bbs/move.php
index e3a7d86f2..a4631addf 100644
--- a/bbs/move.php
+++ b/bbs/move.php
@@ -55,7 +55,7 @@ for ($i=0; $row=sql_fetch_array($result); $i++)
-
+
diff --git a/bbs/new.php b/bbs/new.php
index bbf9ccf96..9e008e861 100644
--- a/bbs/new.php
+++ b/bbs/new.php
@@ -17,6 +17,8 @@ if ($view == "w")
$sql_common .= " and a.wr_id = a.wr_parent ";
else if ($view == "c")
$sql_common .= " and a.wr_id <> a.wr_parent ";
+else
+ $view = '';
$mb_id = isset($_GET['mb_id']) ? ($_GET['mb_id']) : '';
$mb_id = substr(preg_replace('#[^a-z0-9_]#i', '', $mb_id), 0, 20);
diff --git a/bbs/newwin.inc.php b/bbs/newwin.inc.php
index 0e587ce53..2882aa9c3 100644
--- a/bbs/newwin.inc.php
+++ b/bbs/newwin.inc.php
@@ -19,14 +19,11 @@ $result = sql_query($sql, false);
팝업레이어 알림
diff --git a/bbs/password.php b/bbs/password.php
index b29681143..ffd2a55b4 100644
--- a/bbs/password.php
+++ b/bbs/password.php
@@ -51,7 +51,7 @@ $sql = " select wr_subject from {$write_table}
and wr_is_comment = 0 ";
$row = sql_fetch($sql);
-$g5['title'] = $row['wr_subject'];
+$g5['title'] = get_text($row['wr_subject']);
include_once($member_skin_path.'/password.skin.php');
diff --git a/bbs/register_email.php b/bbs/register_email.php
index 4345d4eea..e7fc92537 100644
--- a/bbs/register_email.php
+++ b/bbs/register_email.php
@@ -2,27 +2,28 @@
include_once('./_common.php');
include_once(G5_CAPTCHA_PATH.'/captcha.lib.php');
+$g5['title'] = '메일인증 메일주소 변경';
+include_once('./_head.php');
+
+$mb_id = substr(clean_xss_tags($_GET['mb_id']), 0, 20);
$sql = " select mb_email, mb_datetime, mb_email_certify from {$g5['member_table']} where mb_id = '{$mb_id}' ";
$mb = sql_fetch($sql);
if (substr($mb['mb_email_certify'],0,1)!=0) {
alert("이미 메일인증 하신 회원입니다.", G5_URL);
}
-
-$g5['title'] = '메일인증 메일주소 변경';
-include_once('./_head.php');
?>
- 메일인증을 받지 못한 경우 회원정보의 메일주소를 변경 할 수 있습니다.
+ 메일인증을 받지 못한 경우 회원정보의 메일주소를 변경 할 수 있습니다.
|