Ãë¾àÁ¡ID |
21276 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç PHPCatalog´Â index.php ½ºÅ©¸³Æ®¸¦ ÀÌ¿ëÇÑ SQL Injection Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. PHPCatalog´Â ¸¹Àº ¿î¿µÃ¼Á¦µé¿¡¼ e-commerce catalogµéÀ» °³¹ßÇÏ°í ¿î¿µÇϴµ¥ »ç¿ëµÇ´Â ¼ÒÇÁÆ®¿þ¾îÀÌ´Ù. PHPCatalog 2.6.7 ÀÌÇÏ ¹öÀüµéÀº SQL Injection °ø°Ý¿¡ Ãë¾àÇÏ´Ù. ÀÌ SQL injection Ãë¾àÁ¡Àº PHPCatalog¿¡¼ "index.php" ½ºÅ©¸³Æ®¿¡ Àü´ÞµÇ´Â »ç¿ëÀÚ Á¦°ø ÀԷ°ªÀ» ºÎÀûÀýÇÏ°Ô Ã³¸®ÇÔÀ¸·Î ÀÎÇÏ¿© ¹ß»ýÇÑ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº SQL Äõ¸®°¡ Æ÷ÇÔµÈ "id" º¯¼ö¸¦ "index.php" ½ºÅ©¸³Æ®¿¡ Àü´ÞÇÔÀ¸·Î½á, ¿µÇâÀ» ¹Þ´Â µ¥ÀÌÅͺ£À̽º¸¦ ÀÓÀÇ·Î Á¶ÀÛÇÒ ¼ö ÀÖ´Ù. °á°úÀûÀ¸·Î °ø°ÝÀÚ´Â ½ºÅ©¸³Æ®°¡ ¼öÇàÇÏ´Â SQL ÁúÀǸ¦ ´Ù·ê ¼ö ÀÖÀ¸¸ç µ¥ÀÌÅͺ£À̽º·ÎºÎÅÍ ÆÐ½º¿öµå ÇØ½¬¿Í °°Àº Á¤º¸¸¦ ÃßÃâÇØ ³¾ ¼ö ÀÖ´Ù. ȤÀº (µ¥ÀÌÅͺ£À̽º ¼¹ö¿¡ ÀÖ´Â stored procedure ȤÀº Ãë¾àÁ¡µéÀ» ÅëÇÏ¿©) Ãë¾àÇÑ È£½ºÆ®¿¡ ´ëÇÑ ¾×¼¼½º¸¦ ¾ò¾î³¾ ¼öµµ ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://secunia.com/advisories/10516/ http://www.securitytracker.com/alerts/2003/Dec/1008573.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Siliconsys.com PHPCatalog 2.6.7 ÀÌÇÏ Microsoft Windows Any version Unix Any version Linux Any version |
ÇØ°áÃ¥ |
´ÙÀ½ Siliconsys.com À¥ ÆäÀÌÁö·ÎºÎÅÍ ±¸ÇÒ ¼ö ÀÖ´Â PHPCatalogÀÇ °¡Àå ÃֽйöÀü(2.6.10 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://sourceforge.net/projects/phpcatalog/ |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
9318 (SecurityFocus) |
°ü·Ã URL |
14116 (ISS) |
|