Ãë¾àÁ¡ID |
21251 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç À¥¼¹ö¿¡ ¼³Ä¡µÈ PostNuke´Â SQL injection Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡Àº PostNuke Phoenix v0.723 ÀÌÀü ¹öÀüµé¿¡¼ ¹ß°ßµÇ¾ú´Ù. ¿øÀÎÀº Glossary ¸ðµâÀº »ç¿ëÀÚ Á¦°ø ÀÔ·ÂÀ» ÃæºÐÈ÷ °É·¯³»Áö ¸øÇϱ⠶§¹®ÀÌ´Ù. ÀÌ´Â SQL »ðÀÔ(injection) °ø°Ýµé¿¡ Ãë¾àÇÏ°Ô ÇØ ÁØ´Ù. ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÔÀ¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÁúÀÇ ·ÎÁ÷À» ¼öÁ¤Çϰųª µ¥ÀÌÅͺ£À̽º¸¦ ¼Õ»ó½ÃŰ°Å³ª, ȤÀº PostNuke°¡ »ç¿ëÇÏ´Â µ¥ÀÌÅͺ£À̽ºÀÇ Á¦¾î±ÇÀ» ¾ò¾î³¾ ¼ö ÀÖ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: PostNuke Phoenix 0.721 PostNuke Phoenix 0.722 PostNuke Phoenix 0.723 UNIX/Linux ¸ðµç ¹öÀü Windows ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
´ÙÀ½ »çÀÌÆ®¸¦ ¸¦ ÂüÁ¶ÇÏ¿© PostNukeÀÇ °¡Àå ÃֽйöÀü (0.726 ÀÌ»ó)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. http://en.kbdown.com/32551.html |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
7697 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|