From 9691405fd43dad6d70d3570f34500ffb1f9c6365 Mon Sep 17 00:00:00 2001 From: chicpro Date: Fri, 17 Oct 2014 13:22:26 +0900 Subject: [PATCH] =?UTF-8?q?=EA=B4=80=EB=A6=AC=EC=9E=90=20XSS=20=EB=8C=80?= =?UTF-8?q?=EC=9D=91=20=EC=BD=94=EB=93=9C=20=EC=B6=94=EA=B0=80?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- adm/boardgroupmember_form.php | 2 +- adm/boardgroupmember_list.php | 2 +- adm/index.php | 4 ++-- adm/mail_select_list.php | 4 ++-- adm/mail_test.php | 2 +- adm/member_list.php | 4 ++-- adm/point_list.php | 2 +- lib/common.lib.php | 2 +- 8 files changed, 11 insertions(+), 11 deletions(-) diff --git a/adm/boardgroupmember_form.php b/adm/boardgroupmember_form.php index 01df7dcfa..70d014c82 100644 --- a/adm/boardgroupmember_form.php +++ b/adm/boardgroupmember_form.php @@ -20,7 +20,7 @@ $colspan = 4;
-

아이디 , 이름 , 닉네임

+

아이디 , 이름 , 닉네임

- + - + > diff --git a/adm/point_list.php b/adm/point_list.php index 8d127e1aa..08f44d5b1 100644 --- a/adm/point_list.php +++ b/adm/point_list.php @@ -163,7 +163,7 @@ function point_clear() - +
diff --git a/lib/common.lib.php b/lib/common.lib.php index f14f81dae..4d9660b77 100644 --- a/lib/common.lib.php +++ b/lib/common.lib.php @@ -1199,7 +1199,7 @@ function get_sideview($mb_id, $name='', $email='', $homepage='') global $bo_table, $sca, $is_admin, $member; $email = base64_encode($email); - $homepage = set_http($homepage); + $homepage = set_http(clean_xss_tags($homepage)); $name = preg_replace("/\'/", "", $name); $name = preg_replace("/\'/", "", $name);