diff --git a/adm/shop_admin/couponzonelist_delete.php b/adm/shop_admin/couponzonelist_delete.php index 0fc8911a2..3c6681e56 100644 --- a/adm/shop_admin/couponzonelist_delete.php +++ b/adm/shop_admin/couponzonelist_delete.php @@ -16,8 +16,9 @@ { // 실제 번호를 넘김 $k = $_POST['chk'][$i]; + $ccz_id = (int) $_POST['cz_id'][$k]; - $sql = " delete from {$g5['g5_shop_coupon_zone_table']} where cz_id = '{$_POST['cz_id'][$k]}' "; + $sql = " delete from {$g5['g5_shop_coupon_zone_table']} where cz_id = '{$ccz_id}' "; sql_query($sql); } diff --git a/adm/shop_admin/itemeventformupdate.php b/adm/shop_admin/itemeventformupdate.php index 9603dd62d..5e7f8ea74 100644 --- a/adm/shop_admin/itemeventformupdate.php +++ b/adm/shop_admin/itemeventformupdate.php @@ -19,10 +19,13 @@ if ($ev_himg_del) @unlink(G5_DATA_PATH."/event/{$ev_id}_h"); if ($ev_timg_del) @unlink(G5_DATA_PATH."/event/{$ev_id}_t"); +$ev_skin = preg_replace('#\.+/#', '', $ev_skin); +$ev_mobile_skin = preg_replace('#\.+/#', '', $ev_mobile_skin); + $skin_regex_patten = "^list.[0-9]+\.skin\.php"; -$ev_skin = (preg_match("/$pattern/", $ev_skin) && G5_SHOP_SKIN_PATH.'/'.file_exists($ev_skin)) ? $ev_skin : ''; -$ev_mobile_skin = (preg_match("/$pattern/", $ev_mobile_skin) && G5_MSHOP_SKIN_PATH.'/'.file_exists($ev_mobile_skin)) ? $ev_mobile_skin : ''; +$ev_skin = (preg_match("/$skin_regex_patten/", $ev_skin) && file_exists(G5_SHOP_SKIN_PATH.'/'.$ev_skin)) ? $ev_skin : ''; +$ev_mobile_skin = (preg_match("/$skin_regex_patten/", $ev_mobile_skin) && file_exists(G5_MSHOP_SKIN_PATH.'/'.$ev_mobile_skin)) ? $ev_mobile_skin : ''; $sql_common = " set ev_skin = '$ev_skin', ev_mobile_skin = '$ev_mobile_skin', diff --git a/adm/shop_admin/itemeventlistupdate.php b/adm/shop_admin/itemeventlistupdate.php index 66eddaf4a..7ed95504f 100644 --- a/adm/shop_admin/itemeventlistupdate.php +++ b/adm/shop_admin/itemeventlistupdate.php @@ -8,16 +8,18 @@ for ($i=0; $i