diff --git a/adm/shop_admin/couponzoneform.php b/adm/shop_admin/couponzoneform.php index 2e09bb070..38b3c1535 100644 --- a/adm/shop_admin/couponzoneform.php +++ b/adm/shop_admin/couponzoneform.php @@ -2,6 +2,8 @@ $sub_menu = '400810'; include_once('./_common.php'); +$cz_id = (int) $cz_id; + auth_check($auth[$sub_menu], "w"); $g5['title'] = '쿠폰존 쿠폰관리'; diff --git a/adm/shop_admin/itemcopy.php b/adm/shop_admin/itemcopy.php index 2166c44fb..a3ca5c939 100644 --- a/adm/shop_admin/itemcopy.php +++ b/adm/shop_admin/itemcopy.php @@ -2,6 +2,8 @@ $sub_menu = '400300'; include_once('./_common.php'); +$ca_id = preg_replace('/[^0-9a-z]/i', '', $ca_id); + auth_check($auth[$sub_menu], "r"); $g5['title'] = '상품 복사'; diff --git a/adm/shop_admin/itemuseform.php b/adm/shop_admin/itemuseform.php index 9e7b7f267..a7726e0f7 100644 --- a/adm/shop_admin/itemuseform.php +++ b/adm/shop_admin/itemuseform.php @@ -3,6 +3,8 @@ $sub_menu = '400650'; include_once('./_common.php'); include_once(G5_EDITOR_LIB); +$is_id = preg_replace('/[^0-9]/', '', $is_id); + auth_check($auth[$sub_menu], "w"); $sql = " select * diff --git a/adm/shop_admin/orderlist.php b/adm/shop_admin/orderlist.php index 9fc83a246..83ae3ebbf 100644 --- a/adm/shop_admin/orderlist.php +++ b/adm/shop_admin/orderlist.php @@ -22,6 +22,12 @@ $search = get_search_string($search); if(! preg_match("/^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[1-2][0-9]|3[0-1])$/", $fr_date) ) $fr_date = ''; if(! preg_match("/^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[1-2][0-9]|3[0-1])$/", $to_date) ) $to_date = ''; +$od_misu = preg_replace('/[^0-9a-z]/i', '', $od_misu); +$od_cancel_price = preg_replace('/[^0-9a-z]/i', '', $od_cancel_price); +$od_refund_price = preg_replace('/[^0-9a-z]/i', '', $od_refund_price); +$od_receipt_point = preg_replace('/[^0-9a-z]/i', '', $od_receipt_point); +$od_coupon = preg_replace('/[^0-9a-z]/i', '', $od_coupon); + $sql_search = ""; if ($search != "") { if ($sel_field != "") { diff --git a/adm/shop_admin/orderprintresult.php b/adm/shop_admin/orderprintresult.php index ebb675d7f..ba745b380 100644 --- a/adm/shop_admin/orderprintresult.php +++ b/adm/shop_admin/orderprintresult.php @@ -2,6 +2,9 @@ $sub_menu = '500120'; include_once('./_common.php'); +$fr_date = preg_replace('/[^0-9_\-]/', '', $fr_date); +$to_date = preg_replace('/[^0-9_\-]/', '', $to_date); + auth_check($auth[$sub_menu], "r"); //print_r2($_GET); exit; diff --git a/mobile/shop/item.php b/mobile/shop/item.php index 9b9ee9a4a..367f48a20 100644 --- a/mobile/shop/item.php +++ b/mobile/shop/item.php @@ -2,7 +2,7 @@ include_once('./_common.php'); include_once(G5_LIB_PATH.'/iteminfo.lib.php'); -$it_id = trim($_GET['it_id']); +$it_id = get_search_string(trim($_GET['it_id'])); // 분류사용, 상품사용하는 상품의 정보를 얻음 $sql = " select a.*, diff --git a/mobile/shop/iteminfo.php b/mobile/shop/iteminfo.php index 2356e67ae..7e3587e17 100644 --- a/mobile/shop/iteminfo.php +++ b/mobile/shop/iteminfo.php @@ -1,8 +1,8 @@