[웹드로우] 그누보드5 보안관련 업데이트 5.1.8

페이지 정보

조회 2,635회 작성일 2015-11-25 16:45 URL https://webdraw.kr/notice/406

본문

** 수정내역 ** 

 

CSRF 취약점을 수정했습니다. (한국인터넷진흥원을 통해 이동건님이 알려주셨습니다.) 

 

adm/admin.js 파일이 수정되어 브라우저 캐시를 갱신하지 않으면 정상적인 사용이 불가능할 수 있습니다. 

패치 후 브라우저 화면 새로고침을 여러 번 실행하셔서 캐시를 갱신해주시기 바랍니다. 

 

https://github.com/gnuboard/gnuboard5/commit/a75e00f9e0fabed0baa738be25619ecb2e41a126 

https://github.com/gnuboard/gnuboard5/commit/bb1fd4d3abd938ef0fd872fa2f7accaf6d796734 

https://github.com/gnuboard/gnuboard5/commit/30305d78dc5ce929b143189fb88cc3dc3e019e3e 

https://github.com/gnuboard/gnuboard5/commit/a6327afac4190b1556efdbf05712be2c1a30fa4a 

 

bd57ac5 5.1.8 버전변경 

M      config.php 

db3519a 1:1문의 SMS 발신번호 사전등록제 관련 코드 수정 

M      bbs/qawrite_update.php 

33e9d1e 관리자 CSRF 취약점 수정2 

M      adm/admin.js 

M      adm/admin.lib.php 

M      adm/board_copy.php 

M      adm/contentformupdate.php 

M      adm/contentlist.php 

M      adm/faqformupdate.php 

M      adm/faqlist.php 

M      adm/faqmasterformupdate.php 

M      adm/faqmasterlist.php 

M      adm/index.php 

M      adm/mail_list.php 

M      adm/newwinformupdate.php 

M      adm/newwinlist.php 

M      adm/poll_list.php 

M      adm/sms_admin/config_update.php 

M      adm/sms_admin/sms_write_send.php 

32d09cf 관리자 CSRF 취약점 수정 

M      adm/admin.js 

M      adm/admin.lib.php 

A      adm/ajax.token.php 

M      adm/auth_list.php 

M      adm/auth_list_delete.php 

M      adm/auth_update.php 

M      adm/board_copy.php 

M      adm/board_copy_update.php 

M      adm/board_form.php 

M      adm/board_form_update.php 

M      adm/board_list_update.php 

M      adm/boardgroup_form.php 

M      adm/boardgroup_form_update.php 

M      adm/boardgroup_list.php 

M      adm/boardgroup_list_update.php 

M      adm/boardgroupmember_form.php 

M      adm/boardgroupmember_update.php 

M      adm/config_form.php 

M      adm/config_form_update.php 

M      adm/contentform.php 

M      adm/contentformupdate.php 

M      adm/faqform.php 

M      adm/faqformupdate.php 

M      adm/faqmasterform.php 

M      adm/faqmasterformupdate.php 

M      adm/mail_delete.php 

M      adm/mail_form.php 

M      adm/mail_select_list.php 

M      adm/mail_select_update.php 

M      adm/mail_update.php 

M      adm/member_delete.php 

M      adm/member_form.php 

M      adm/member_form_update.php 

M      adm/member_list.php 

M      adm/member_list_delete.php 

M      adm/menu_list.php 

M      adm/menu_list_update.php 

M      adm/newwinform.php 

M      adm/newwinformupdate.php 

M      adm/point_list.php 

M      adm/point_list_delete.php 

M      adm/point_update.php 

M      adm/poll_delete.php 

M      adm/poll_form.php 

M      adm/poll_form_update.php 

M      adm/poll_list.php 

M      adm/qa_config.php 

M      adm/qa_config_update.php 

M      adm/theme_update.php 

976c9d0 모바일 제목 설정 적용되도록 수정 

M      bbs/board.php 

M      bbs/new.php 

M      bbs/search.php 

M      bbs/write.php 

M      mobile/skin/board/basic/list.skin.php 

M      mobile/skin/board/basic/view.skin.php 

M      mobile/skin/board/gallery/list.skin.php 

M      mobile/skin/board/gallery/view.skin.php 

M      theme/basic/mobile/skin/board/basic/list.skin.php 

M      theme/basic/mobile/skin/board/basic/view.skin.php 

M      theme/basic/mobile/skin/board/gallery/list.skin.php 

M      theme/basic/mobile/skin/board/gallery/view.skin.php 


MENU