English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21292
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç Ultimate PHP Board¿¡´Â ºñÀΰ¡µÈ Á¤º¸µéÀÇ ³ëÃâ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
UPB(Ultimate PHP Board)´Â Windows¿Í Unix ¹× Linux ¿î¿µÃ¼Á¦¿¡¼­ µ¿ÀÛÇÏ´Â ¿ÀÇ ¼Ò½º PHP °Ô½ÃÆÇÀ¸·Î¼­ ¹«·á·Î »ç¿ë °¡´ÉÇÏ´Ù. 'data_dir'(<UPD ¼³Ä¡Æú´õ/db>)¿¡ À§Ä¡ÇÑ ÆÄÀϵéÀº µðÆúÆ®·Î ¿ø°ÝÀ¸·Î Á¢±ÙÀÌ °¡´ÉÇϵµ·Ï ¼³Á¤µÇ¾î ÀÖ´Ù. ÀÌ µð·ºÅ丮¿¡´Â °Ô½ÃÆÇ »ç¿ëÀÚµéÀÇ °³ÀÎÁ¤º¸µéÀÌ ´ã°ÜÁ® ÀÖ´Â ÆÄÀϵéÀÌ Á¸ÀçÇϱ⠶§¹®¿¡, ¾ÇÀÇÀûÀÎ °ø°ÝÀڵ鿡°Ô Áß¿äÇÑ Á¤º¸¸¦ ³ëÃâÇÒ ¼ö ÀÖ°Ô µÈ´Ù. ÀÌ Ãë¾àÁ¡À» ÅëÇØ ȹµæµÈ Á¤º¸µéÀº °ø°ÝÀڵ鿡 ÀÇÇØ º¸´Ù Áö´ÉÀûÀÎ °ø°Ý ¼öÇàÀ» À§ÇØ ÀÌ¿ëµÉ ¼ö ÀÖ´Ù.

´ÙÀ½°ú °°Àº ¹æ¹ýÀ¸·Î, ÀÌ Ãë¾àÁ¡À» ¼öµ¿À¸·Î Å×½ºÆ®ÇØ º¼ ¼ö ÀÖ´Ù.
- http://[target]/upd/db/users.dat
- http://[target]/board/db/user.dat

* Âü°í »çÀÌÆ®:
http://www.osvdb.org/4928
http://archives.neohapsis.com/archives/bugtraq/2002-10/0016.html
http://archives.neohapsis.com/archives/bugtraq/2002-12/0071.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
MyUPB Ultimate PHP Board 1.9
MyUPB Ultimate PHP Board 1.8
MyUPB Ultimate PHP Board 1.7
MyUPB Ultimate PHP Board 1.6
MyUPB Ultimate PHP Board 1.5
Microsoft Windows Any version
Unix Any version
ÇØ°áÃ¥ MyUPB À¥ »çÀÌÆ®ÀÎ http://www.myupb.com ·ÎºÎÅÍ ÀÌ Ãë¾àÁ¡ÀÌ ÇØ°áµÈ ¹öÀü 1.9.6 ÀÌ»óÀ» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î, ".htaccess" ¸¦ ÅëÇØ '/db/' µð·ºÅ丮¸¦ º¸È£Çϰųª Ultimate PHP Board ¼Ò½º¸¦ ¼öÁ¤ÇÏ¿© 'users.dat' ÆÄÀÏÀÌ À¥ ¼­¹ö ·çÆ® ¹Û¿¡ À§Ä¡Çϵµ·Ï º¯°æÇÑ´Ù.
°ü·Ã URL CVE-2002-2276 (CVE)
°ü·Ã URL 6333 (SecurityFocus)
°ü·Ã URL 10788 (ISS)