Ãë¾àÁ¡ID |
21255 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç À¥¼¹ö¿¡ ¼³Ä¡µÈ phpWebSite ÆÐŰÁö´Â ´ÙÁßÀÇ Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ´Ù. phpWebSite´Â À©µµ¿ìÁî¿Í Unix ±â¹ÝÀÇ ¿î¿µÃ¼Á¦ ¿ëÀ¸·Î PHP·Î ¾º¾îÁø °ø°³ ¼Ò½º·Î µÈ À¥ ÄÜÅÙÆ® °ü¸® ÅøÀÌ´Ù. ÀÌ Á¦Ç°¿¡ ÀÖ´Â ´ÙÁßÀÇ º¸¾È Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ Ãë¾àÇÑ ¼¹ö¿¡¼ ¾îÇø®ÄÉÀÌ¼Ç »ç¿ëÀÚÀÇ ±ÇÇÑÀ» °¡Áö°í ÀÓÀÇÀÇ SQL ÁúÀǵéÀ» ½ÇÇà½ÃŰ°Å³ª ȤÀº ¼¹ö¸¦ ¿ÏÀüÈ÷ ÀÛµ¿ÁßÁö ½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. °ø°ÝÀÚ´Â ¶ÇÇÑ Cross-Site Scripting Ãë¾àÁ¡À» µµ¿ëÇÏ¿© Èñ»ýÀÚÀÇ ÄíŰ ±â¹ÝÀÇ ÀÎÁõ ½Å¿ëÁ¤º¸¸¦ ÈÉÃij»°Å³ª ´Ù¸¥ Áß¿äÇÑ Á¤º¸¸¦ ¾ò¾î³¾ ¼öµµ ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/archive/1/332561 http://archives.neohapsis.com/archives/bugtraq/2003-08/0097.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: phpWebSite version 0.9.x ÀÌÇÏ Windows Any version Unix/Linux Any version |
ÇØ°áÃ¥ |
´ÙÀ½ »çÀÌÆ®·ÎºÎÅÍ ÃֽйöÀüÀÇ phpWebSite(1.0.0 ÀÌ»ó)¸¦ ´Ù¿î·Îµå ¹ÞÀ» ¼ö ÀÖ´Ù: http://phpwebsite.appstate.edu/index.php?menu=1 |
°ü·Ã URL |
CVE-2003-0735,CVE-2003-0736,CVE-2003-0737,CVE-2003-0738 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
12891,12894,12895,12896 (ISS) |
|