English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21276
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç PHPCatalog´Â index.php ½ºÅ©¸³Æ®¸¦ ÀÌ¿ëÇÑ SQL Injection Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. PHPCatalog´Â ¸¹Àº ¿î¿µÃ¼Á¦µé¿¡¼­ e-commerce catalogµéÀ» °³¹ßÇÏ°í ¿î¿µÇϴµ¥ »ç¿ëµÇ´Â ¼ÒÇÁÆ®¿þ¾îÀÌ´Ù. PHPCatalog 2.6.7 ÀÌÇÏ ¹öÀüµéÀº SQL Injection °ø°Ý¿¡ Ãë¾àÇÏ´Ù. ÀÌ SQL injection Ãë¾àÁ¡Àº PHPCatalog¿¡¼­ "index.php" ½ºÅ©¸³Æ®¿¡ Àü´ÞµÇ´Â »ç¿ëÀÚ Á¦°ø ÀԷ°ªÀ» ºÎÀûÀýÇÏ°Ô Ã³¸®ÇÔÀ¸·Î ÀÎÇÏ¿© ¹ß»ýÇÑ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº SQL Äõ¸®°¡ Æ÷ÇÔµÈ "id" º¯¼ö¸¦ "index.php" ½ºÅ©¸³Æ®¿¡ Àü´ÞÇÔÀ¸·Î½á, ¿µÇâÀ» ¹Þ´Â µ¥ÀÌÅͺ£À̽º¸¦ ÀÓÀÇ·Î Á¶ÀÛÇÒ ¼ö ÀÖ´Ù. °á°úÀûÀ¸·Î °ø°ÝÀÚ´Â ½ºÅ©¸³Æ®°¡ ¼öÇàÇÏ´Â SQL ÁúÀǸ¦ ´Ù·ê ¼ö ÀÖÀ¸¸ç µ¥ÀÌÅͺ£À̽º·ÎºÎÅÍ ÆÐ½º¿öµå ÇØ½¬¿Í °°Àº Á¤º¸¸¦ ÃßÃâÇØ ³¾ ¼ö ÀÖ´Ù. ȤÀº (µ¥ÀÌÅͺ£À̽º ¼­¹ö¿¡ ÀÖ´Â stored procedure ȤÀº Ãë¾àÁ¡µéÀ» ÅëÇÏ¿©) Ãë¾àÇÑ È£½ºÆ®¿¡ ´ëÇÑ ¾×¼¼½º¸¦ ¾ò¾î³¾ ¼öµµ ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://secunia.com/advisories/10516/
http://www.securitytracker.com/alerts/2003/Dec/1008573.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Siliconsys.com PHPCatalog 2.6.7 ÀÌÇÏ
Microsoft Windows Any version
Unix Any version
Linux Any version
ÇØ°áÃ¥ ´ÙÀ½ Siliconsys.com À¥ ÆäÀÌÁö·ÎºÎÅÍ ±¸ÇÒ ¼ö ÀÖ´Â PHPCatalogÀÇ °¡Àå ÃֽйöÀü(2.6.10 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://sourceforge.net/projects/phpcatalog/
°ü·Ã URL (CVE)
°ü·Ã URL 9318 (SecurityFocus)
°ü·Ã URL 14116 (ISS)