English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21237
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç ZeroboardÀÇ _head.php´Â ¿ø°ÝÁöÀÇ °ø°ÝÀڵ鿡°Ô ÀÓÀÇÀÇ ¸í·ÉÀ» ½ÇÇàÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
Zeroboard´Â Linux¿Í Unix Ç÷§Æû¿¡¼­ »ç¿ëÇÒ ¼ö ÀÖ´Â PHP À¥ °Ô½ÃÆÇ ÆÐŰÁöÀÌ´Ù. Zeroboard´Â Çѱ¹¿¡¼­ °¡Àå ÀαâÀÖ´Â PHP À¥ °Ô½ÃÆÇ ÁßÀÇ ÇϳªÀÌ´Ù.
ƯÁ¤ ȯ°æ ÇÏ¿¡¼­, Zeroboard´Â ÀÓÀÇÀÇ PHP ÆÄÀϵéÀ» Æ÷ÇÔ(include) ÇÒ ¼ö ÀÖ´Ù. _head.php ÆÄÀÏÀº ÀԷ¿¡ ´ëÇÑ Ã¼Å©¿¡ ¹®Á¦¸¦ °¡Áö°í ÀÖ´Ù. Php.ini¿¡ ÀÖ´Â "allow_url_fopen" º¯¼ö¿Í "register_globals" º¯¼ö°¡ "On" À¸·Î ¼³Á¤µÇ¾î ÀÖÀ» ¶§, _head.php ½ºÅ©¸³Æ®¸¦ ÅëÇØ ¿ÜºÎ URL·ÎºÎÅÍ ÀÓÀÇÀÇ PHP include ÆÄÀÏÀ» ·Îµå(load)ÇÒ ¼ö ÀÖ´Ù.

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Zeroboard 4.0 ~ 4.1 pl2
UNIX/Linux ¸ðµç ¹öÀü
ÇØ°áÃ¥ Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î php.ini ÆÄÀÏ¿¡¼­ 'allow_url_fopen = off' ±×¸®°í 'register_globals = off' ¸¦ ¼³Á¤ÇÑ´Ù.
°ü·Ã URL CVE-2002-1704 (CVE)
°ü·Ã URL 5028 (SecurityFocus)
°ü·Ã URL (ISS)