English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21269
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥¼­¹ö¿¡ ¼³Ä¡µÈ phpBB´Â search.php¸¦ ÀÌ¿ëÇÑ SQL injection Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
phpBB´Â °Ô½ÃÆÇ(bulletin board)À» À§ÇÑ ¿ÀÇ ¼Ò½º ¼ÒÇÁÆ®¿þ¾î ÆÐŰÁö·Î½á µ¥ÀÌÅͺ£À̽º·Î´Â MySQL, MS-SQL, PostgreSQL, Access/ODBC µîÀ» »ç¿ëÇÑ´Ù. ÀÌ SQL injection Ãë¾àÁ¡Àº phpBB¿¡¼­ "search.php" ½ºÅ©¸³Æ®¿¡ Àü´ÞµÇ´Â »ç¿ëÀÚ Á¦°ø ÀԷ°ªÀ» ºÎÀûÀýÇÏ°Ô Ã³¸®ÇÔÀ¸·Î ÀÎÇÏ¿© ¹ß»ýÇÑ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº SQL Äõ¸®°¡ Æ÷ÇÔµÈ search_id º¯¼ö¸¦ "search.php" ½ºÅ©¸³Æ®¿¡ Àü´ÞÇÔÀ¸·Î½á, phpBB°¡ »ç¿ëÇÏ´Â µ¥ÀÌÅͺ£À̽º¸¦ ÀÓÀÇ·Î Á¶ÀÛÇÒ ¼ö ÀÖ´Ù. °á°úÀûÀ¸·Î °ø°ÝÀÚ´Â ½ºÅ©¸³Æ®°¡ ¼öÇàÇÏ´Â SQL ÁúÀǸ¦ ´Ù·ê ¼ö ÀÖÀ¸¸ç µ¥ÀÌÅͺ£À̽º·ÎºÎÅÍ ÆÐ½º¿öµå ÇØ½¬¿Í °°Àº Á¤º¸¸¦ ÃßÃâÇØ ³¾ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/345872
http://www.securityfocus.com/archive/1/345946

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
phpBB 2.0.6 ÀÌÇÏÀÇ ¹öÀüµé
Linux ¸ðµç ¹öÀü
Unix ¸ðµç ¹öÀü
Windows ¸ðµç ¹öÀü
ÇØ°áÃ¥ ´ÙÀ½ »çÀÌÆ®·ÎºÎÅÍ phpBBÀÇ °¡Àå ÃֽйöÀü(2.0.6 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.phpbb.com/downloads.php

Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î, ´ÙÀ½ »çÀÌÆ®·ÎºÎÅÍ phpBB Æ÷·³ÀÌ Á¦°øÇÏ´Â ÀÓ½ÃÀûÀÎ Á¶Ä¡¹æ¹ý(fix)À» ±¸ÇÒ ¼ö ÀÖ´Ù:
http://www.phpbb.com/phpBB/viewtopic.php?t=153818
°ü·Ã URL CVE-2003-1216 (CVE)
°ü·Ã URL 9122 (SecurityFocus)
°ü·Ã URL 13867 (ISS)