Ãë¾àÁ¡ID |
21303 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç À¥ ¼¹ö¿¡ ¼³Ä¡µÈ Invision Gallery ¿¡´Â 'index.php' ½ºÅ©¸³Æ®¸¦ ÅëÇÑ SQL injection Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Invision Gallery´Â PHP ±â¹Ý À¥ Æ÷·³(forum) ¼ÒÇÁÆ®¿þ¾î ÆÐŰÁöÀÎ Invision Power Board¸¦ À§ÇÑ Æ÷Åä °¶·¯¸® Ç÷¯±×ÀÎ(plug-in) ÀÌ´Ù. ÀÌ Invision Gallery 1.0.1 ¹öÀü¿¡´Â 'index.php' ½ºÅ©¸³Æ®¸¦ ÅëÇØ ¾×¼¼½ºµÇ´Â °¶·¯¸® ¸ðµâÀÇ 'img', 'cat', 'sort_key', 'order_key', 'user', 'album' ÆÄ¶ó¹ÌÅ͵éÀ» ÅëÇØ ÀԷµǴ »ç¿ëÀÚ ÀÔ·Â µ¥ÀÌÅ͸¦ ÃæºÐÈ÷ ÇÊÅ͸µÇÏÁö ¸øÇÔÀ¸·Î ÀÎÇÏ¿©, SQL Injection Ãë¾àÁ¡ÀÌ ¹ß»ýÇÒ ¼ö ÀÖ´Ù. ´ÙÀ½°ú °°ÀÌ ¿ø°ÝÁö °ø°ÝÀÚµéÀº 'index.php' ½ºÅ©¸³Æ®¸¦ ÅëÇØ ÈÄÀ§¿¡ À§Ä¡ÇÑ µ¥ÀÌÅͺ£À̽º¿¡ ¾ÇÀÇÀûÀÎ SQL ¸í·ÉÀ» Àü´ÞÇÔÀ¸·Î½á, ÈÄÀ§ µ¥ÀÌÅͺ£À̽º »óÀÇ Á¤º¸µéÀ» º¯°æÇϰųª Ãß°¡, »èÁ¦ÇÒ ¼ö ÀÖ´Ù.
index.php?act=module&module=gallery&cmd=si&img=[SQL] index.php?act=module&module=gallery&cmd=editimg&img=[SQL] index.php?act=module&module=gallery&cmd=ecard&img=[SQL] index.php?act=module&module=gallery&cmd=moveimg&img=[SQL] index.php?act=module&module=gallery&cmd=delimg&img=[SQL] index.php?act=module&module=gallery&cmd=post&cat=[SQL] index.php?act=module&module=gallery&cmd=sc&op=user&sort_key=[SQL] index.php?act=module&module=gallery&cmd=sc&op=user&sort_key=date&order_key=[SQL] index.php?act=module&module=gallery&cmd=favs&op=add&img=[SQL] index.php?act=module&module=gallery&cmd=slideshow&cat=[SQL] index.php?act=module&module=gallery&cmd=user&user=[SQL]&op=view_album&album=1 index.php?act=module&module=gallery&cmd=user&user=[SQL] index.php?act=module&module=gallery&cmd=user&user=1&op=view_album&album=[SQL]
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/bugtraq/2004-03/0210.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Invision Gallery 1.0.1 ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
´ÙÀ½ »çÀÌÆ®¸¦ Âü°íÇÏ¿© ÃֽйöÀüÀÇ Invision Gallery·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù. http://www.invisionpower.com/products/gallery/ |
°ü·Ã URL |
CVE-2004-1835 (CVE) |
°ü·Ã URL |
9944 (SecurityFocus) |
°ü·Ã URL |
15566 (ISS) |
|