English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21255
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç À¥¼­¹ö¿¡ ¼³Ä¡µÈ phpWebSite ÆÐŰÁö´Â ´ÙÁßÀÇ Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ´Ù.
phpWebSite´Â À©µµ¿ìÁî¿Í Unix ±â¹ÝÀÇ ¿î¿µÃ¼Á¦ ¿ëÀ¸·Î PHP·Î ¾º¾îÁø °ø°³ ¼Ò½º·Î µÈ À¥ ÄÜÅÙÆ® °ü¸® ÅøÀÌ´Ù. ÀÌ Á¦Ç°¿¡ ÀÖ´Â ´ÙÁßÀÇ º¸¾È Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ Ãë¾àÇÑ ¼­¹ö¿¡¼­ ¾îÇø®ÄÉÀÌ¼Ç »ç¿ëÀÚÀÇ ±ÇÇÑÀ» °¡Áö°í ÀÓÀÇÀÇ SQL ÁúÀǵéÀ» ½ÇÇà½ÃŰ°Å³ª ȤÀº ¼­¹ö¸¦ ¿ÏÀüÈ÷ ÀÛµ¿ÁßÁö ½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. °ø°ÝÀÚ´Â ¶ÇÇÑ Cross-Site Scripting Ãë¾àÁ¡À» µµ¿ëÇÏ¿© Èñ»ýÀÚÀÇ ÄíŰ ±â¹ÝÀÇ ÀÎÁõ ½Å¿ëÁ¤º¸¸¦ ÈÉÃij»°Å³ª ´Ù¸¥ Áß¿äÇÑ Á¤º¸¸¦ ¾ò¾î³¾ ¼öµµ ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/332561
http://archives.neohapsis.com/archives/bugtraq/2003-08/0097.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
phpWebSite version 0.9.x ÀÌÇÏ
Windows Any version
Unix/Linux Any version
ÇØ°áÃ¥ ´ÙÀ½ »çÀÌÆ®·ÎºÎÅÍ ÃֽйöÀüÀÇ phpWebSite(1.0.0 ÀÌ»ó)¸¦ ´Ù¿î·Îµå ¹ÞÀ» ¼ö ÀÖ´Ù:
http://phpwebsite.appstate.edu/index.php?menu=1
°ü·Ã URL CVE-2003-0735,CVE-2003-0736,CVE-2003-0737,CVE-2003-0738 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL 12891,12894,12895,12896 (ISS)