Ãë¾àÁ¡ID |
21282 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç phpMyAdmin ¼ÒÇÁÆ®¿þ¾î´Â µð·ºÅ丮 Ž»ö Ãë¾àÁ¡(2)¸¦ °¡Áö°í ÀÖ´Ù. phpMyAdmin´Â À¥À» ÅëÇØ MySQL¸¦ °ü¸®ÇÏ·Á´Â ¸ñÀûÀÇ PHP·Î Á¦ÀÛµÈ ÅøÀÌ´Ù. ÇöÀç ÀÌ ÅøÀº µ¥ÀÌÅͺ£À̽ºÀÇ »ý¼º°ú »èÁ¦, Å×À̺íÀÇ »ý¼º/»èÁ¦/º¯°æ, ÇʵåÀÇ »èÁ¦/ÆíÁý/Ãß°¡, ÀÓÀÇÀÇ SQL ¹®ÀÇ ½ÇÇà, Çʵå»óÀÇ Å° °ü¸® ±â´É µîÀ» Á¦°øÇÑ´Ù. phpMyAdmin 2.5.5-pl1 ÀÌÇÏÀÇ ¹öÀüµé¿¡ ÀÖ´Â 'export.php' »ùÇà ½ºÅ©¸³Æ®´Â »ç¿ëÀÚ°¡ ÀÔ·ÂÇÏ´Â "what" ÆÄ¶ó¹ÌÅÍ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ Å¸´ç¼º °Ë»ç·Î ÀÎÇÏ¿© À¥ ¼¹ö¿¡ Á¸ÀçÇÏ´Â ÀÓÀÇÀÇ ÆÄÀÏÀ» ÀÐÀ» ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ÀÌ Ãë¾àÁ¡À» µµ¿ëÇϱâ À§ÇØ ¿ø°ÝÁö °ø°ÝÀÚµéÀº ´ÙÀ½°ú °°ÀÌ "dot dot" ½ÃÄö½º(/../)¿Í Àß ¾Ë·ÁÁø ÆÄÀÏ¿¡ ³Î ¹ÙÀÌÆ®(%00)¸¦ µ¡ºÙ¿© "export.php" ¿äûÀ» ¼¹ö¿¡ Àü´ÞÇÑ´Ù.
http://[targetserver]/export.php?what=../../..../../../../../../../etc/passwd%00
À§ÀÇ ¿äûÀ» ÅëÇØ °ø°ÝÀÚ´Â ¼¹ö ³»ÀÇ ÆÐ½º¿öµå ÆÄÀÏÀ» ÀÐÀ» ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/archive/1/352378
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: phpMyAdmin 2.5.5-pl1 ÀÌÇÏÀÇ ¹öÀüµé Windows Any version UNIX/Linux Any version |
ÇØ°áÃ¥ |
´ÙÀ½ phpMyAdmin ProjectÀÇ °ø½Ä À¥ »çÀÌÆ®¿¡¼ phpMyAdminÀÇ °¡Àå ÃֽйöÀü(2.5.6-rc1 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.phpmyadmin.net/home_page/ |
°ü·Ã URL |
CVE-2004-0129 (CVE) |
°ü·Ã URL |
9564 (SecurityFocus) |
°ü·Ã URL |
15021 (ISS) |
|