Merge pull request #1019 from stellar12/develop

Vid parameter 이용한 취약점 발생 가능성 방지
This commit is contained in:
bnu 2014-10-20 19:06:41 +09:00
commit 3ecf7be593

View file

@ -1289,10 +1289,14 @@ class Context
{
$result[$k] = !preg_match('/^[0-9,]+$/', $v) ? (int) $v : $v;
}
elseif($key === 'mid' || $key === 'vid' || $key === 'search_keyword')
elseif($key === 'mid' || $key === 'search_keyword')
{
$result[$k] = htmlspecialchars($v, ENT_COMPAT | ENT_HTML401, 'UTF-8', FALSE);
}
elseif($key === 'vid')
{
$result[$k] = urlencode($v);
}
else
{
$result[$k] = $v;