English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21275
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç osCommerce´Â create_account_process.php ½ºÅ©¸³Æ®¸¦ ÀÌ¿ëÇÑ SQL Injection Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. osCommerce´Â °ø°³ ¼Ò½º ´Üü¿¡ ÀÇÇØ °³¹ßÀÌ ÁøÇàµÇ¾î ¿Â ¿Â¶óÀÎ ¼îÇÎÀ» À§ÇÑ e-commerce ¼Ö·ç¼ÇÀÌ´Ù. osCommerce 2.2ms1 ÀÌÇÏ ¹öÀüµéÀº SQL Injection °ø°Ý¿¡ Ãë¾àÇÏ´Ù. ÀÌ SQL injection Ãë¾àÁ¡Àº PHP-Nuke¿¡¼­ "create_account_process.php" ½ºÅ©¸³Æ®¿¡ Àü´ÞµÇ´Â »ç¿ëÀÚ Á¦°ø ÀԷ°ªÀ» ºÎÀûÀýÇÏ°Ô Ã³¸®ÇÔÀ¸·Î ÀÎÇÏ¿© ¹ß»ýÇÑ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº SQL Äõ¸®°¡ Æ÷ÇÔµÈ "country" º¯¼ö¸¦ "create_account_process.php" ½ºÅ©¸³Æ®¿¡ Àü´ÞÇÔÀ¸·Î½á, ¿µÇâÀ» ¹Þ´Â µ¥ÀÌÅͺ£À̽º¸¦ ÀÓÀÇ·Î Á¶ÀÛÇÒ ¼ö ÀÖ´Ù. °á°úÀûÀ¸·Î °ø°ÝÀÚ´Â ½ºÅ©¸³Æ®°¡ ¼öÇàÇÏ´Â SQL ÁúÀǸ¦ ´Ù·ê ¼ö ÀÖÀ¸¸ç µ¥ÀÌÅͺ£À̽º·ÎºÎÅÍ ÆÐ½º¿öµå ÇØ½¬¿Í °°Àº Á¤º¸¸¦ ÃßÃâÇØ ³¾ ¼ö ÀÖ´Ù. ȤÀº (µ¥ÀÌÅͺ£À̽º ¼­¹ö¿¡ ÀÖ´Â stored procedure ȤÀº Ãë¾àÁ¡µéÀ» ÅëÇÏ¿©) Ãë¾àÇÑ È£½ºÆ®¿¡ ´ëÇÑ ¾×¼¼½º¸¦ ¾ò¾î³¾ ¼öµµ ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/347591

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
osCommerce ¹öÀü 2.2ms1 ÀÌÇÏ
ÇØ°áÃ¥ ´ÙÀ½ osCommerce ´Ù¿î·Îµå ÆäÀÌÁö·ÎºÎÅÍ ±¸ÇÒ ¼ö ÀÖ´Â osCommerceÀÇ °¡Àå ÃֽйöÀü(2.2ms2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.oscommerce.com/solutions/downloads
°ü·Ã URL (CVE)
°ü·Ã URL 9211 (SecurityFocus)
°ü·Ã URL (ISS)