| [À¥È£½ºÆÃ] Á¦·Îº¸µå 4 pl9 ¹öÀü |
|---|
|
÷ºÎÆÄÀÏ :
|
|
¾È³çÇϼ¼¿ä. ¾ÆÀ̳×ÀÓÁîÀÔ´Ï´Ù. Á¦·Îº¸µå 4ÀÇ ÃֽůÐÄ¡¹öÀüÀÌ °ø°³µÇ¾ú½À´Ï´Ù. ¿øº»¸µÅ©´Â ¾Æ·¡¿Í °°½À´Ï´Ù. : http://www.xpressengine.com/17727425#32 º¯°æ»çÇ×Àº ´ÙÀ½°ú °°½À´Ï´Ù. ---------------------------------------------------------- ÃÖ±Ù ¹ß°ßµÈ Á¦·Îº¸µå4ÀÇ º¸¾È Ãë¾àÁ¡À» ÆÐÄ¡ÇÏ¿´½À´Ï´Ù. ´ÙÀ½°ú °°Àº ÆÄÀÏÀÇ ³»¿ëÀÌ º¯°æµÇ¾ú½À´Ï´Ù. 1. view.php 65 line ¿ø ÄÚµå : @setcookie('zb_s_check', $secret_str) ¼öÁ¤ : $HTTP_SESSION_VARS['zb_s_check'] = $secret_str; 2. write_ok.php 3¹øÂ° ÁÙ Ãß°¡ : $del_que1 = $del_que2 = null; 3. write.php 73 line ¿ø ÄÚµå : if($data[is_secret]&&!$is_admin&&$data[ismember]!=$member[no]&&$HTTP_COOKIE_VARS[zb_s_check]!=$setup[no]."_".$no) ... ¼öÁ¤ ÄÚµå : if($data[is_secret]&&!$is_admin&&$data[ismember]!=$member[no]&&$HTTP_SESSION_VARS[zb_s_check]!=$setup[no]."_".$no) ... 4. include/print_category.php 2¹øÂ° ÁÙ Ãß°¡ Ãß°¡ ÄÚµå : if(!defined("_zb_lib_included")) return; 6. include/write.php 2¹øÂ°ÁÙ Ãß°¡ Ãß°¡ ÄÚµå : if(!defined("_zb_lib_included")) return; ÀÚ¼¼ÇÑ ÆÐÄ¡ ³»¿ëÀº zb4.secret.patch.2009.02.29.txt ¸¦ º¸½Ã¸é µË´Ï´Ù. ---------------------------------------------------------- |