SQL Injection 취약점 수정
This commit is contained in:
@ -149,6 +149,7 @@ if (!$sst) {
|
||||
$sst = preg_match("/^(wr_datetime|wr_hit|wr_good|wr_nogood)$/i", $sst) ? $sst : "";
|
||||
}
|
||||
|
||||
$sql_order = '';
|
||||
if ($sst) {
|
||||
$sql_order = " order by {$sst} {$sod} ";
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user