Ãë¾àÁ¡ID |
21269 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç À¥¼¹ö¿¡ ¼³Ä¡µÈ phpBB´Â search.php¸¦ ÀÌ¿ëÇÑ SQL injection Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. phpBB´Â °Ô½ÃÆÇ(bulletin board)À» À§ÇÑ ¿ÀÇ ¼Ò½º ¼ÒÇÁÆ®¿þ¾î ÆÐŰÁö·Î½á µ¥ÀÌÅͺ£À̽º·Î´Â MySQL, MS-SQL, PostgreSQL, Access/ODBC µîÀ» »ç¿ëÇÑ´Ù. ÀÌ SQL injection Ãë¾àÁ¡Àº phpBB¿¡¼ "search.php" ½ºÅ©¸³Æ®¿¡ Àü´ÞµÇ´Â »ç¿ëÀÚ Á¦°ø ÀԷ°ªÀ» ºÎÀûÀýÇÏ°Ô Ã³¸®ÇÔÀ¸·Î ÀÎÇÏ¿© ¹ß»ýÇÑ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº SQL Äõ¸®°¡ Æ÷ÇÔµÈ search_id º¯¼ö¸¦ "search.php" ½ºÅ©¸³Æ®¿¡ Àü´ÞÇÔÀ¸·Î½á, phpBB°¡ »ç¿ëÇÏ´Â µ¥ÀÌÅͺ£À̽º¸¦ ÀÓÀÇ·Î Á¶ÀÛÇÒ ¼ö ÀÖ´Ù. °á°úÀûÀ¸·Î °ø°ÝÀÚ´Â ½ºÅ©¸³Æ®°¡ ¼öÇàÇÏ´Â SQL ÁúÀǸ¦ ´Ù·ê ¼ö ÀÖÀ¸¸ç µ¥ÀÌÅͺ£À̽º·ÎºÎÅÍ ÆÐ½º¿öµå ÇØ½¬¿Í °°Àº Á¤º¸¸¦ ÃßÃâÇØ ³¾ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/archive/1/345872 http://www.securityfocus.com/archive/1/345946
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: phpBB 2.0.6 ÀÌÇÏÀÇ ¹öÀüµé Linux ¸ðµç ¹öÀü Unix ¸ðµç ¹öÀü Windows ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
´ÙÀ½ »çÀÌÆ®·ÎºÎÅÍ phpBBÀÇ °¡Àå ÃֽйöÀü(2.0.6 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.phpbb.com/downloads.php
Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î, ´ÙÀ½ »çÀÌÆ®·ÎºÎÅÍ phpBB Æ÷·³ÀÌ Á¦°øÇÏ´Â ÀÓ½ÃÀûÀÎ Á¶Ä¡¹æ¹ý(fix)À» ±¸ÇÒ ¼ö ÀÖ´Ù: http://www.phpbb.com/phpBB/viewtopic.php?t=153818 |
°ü·Ã URL |
CVE-2003-1216 (CVE) |
°ü·Ã URL |
9122 (SecurityFocus) |
°ü·Ã URL |
13867 (ISS) |
|