English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21303
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥ ¼­¹ö¿¡ ¼³Ä¡µÈ Invision Gallery ¿¡´Â 'index.php' ½ºÅ©¸³Æ®¸¦ ÅëÇÑ SQL injection Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
Invision Gallery´Â PHP ±â¹Ý À¥ Æ÷·³(forum) ¼ÒÇÁÆ®¿þ¾î ÆÐŰÁöÀÎ Invision Power Board¸¦ À§ÇÑ Æ÷Åä °¶·¯¸® Ç÷¯±×ÀÎ(plug-in) ÀÌ´Ù. ÀÌ Invision Gallery 1.0.1 ¹öÀü¿¡´Â 'index.php' ½ºÅ©¸³Æ®¸¦ ÅëÇØ ¾×¼¼½ºµÇ´Â °¶·¯¸® ¸ðµâÀÇ 'img', 'cat', 'sort_key', 'order_key', 'user', 'album' ÆÄ¶ó¹ÌÅ͵éÀ» ÅëÇØ ÀԷµǴ »ç¿ëÀÚ ÀÔ·Â µ¥ÀÌÅ͸¦ ÃæºÐÈ÷ ÇÊÅ͸µÇÏÁö ¸øÇÔÀ¸·Î ÀÎÇÏ¿©, SQL Injection Ãë¾àÁ¡ÀÌ ¹ß»ýÇÒ ¼ö ÀÖ´Ù. ´ÙÀ½°ú °°ÀÌ ¿ø°ÝÁö °ø°ÝÀÚµéÀº 'index.php' ½ºÅ©¸³Æ®¸¦ ÅëÇØ ÈÄÀ§¿¡ À§Ä¡ÇÑ µ¥ÀÌÅͺ£À̽º¿¡ ¾ÇÀÇÀûÀÎ SQL ¸í·ÉÀ» Àü´ÞÇÔÀ¸·Î½á, ÈÄÀ§ µ¥ÀÌÅͺ£À̽º »óÀÇ Á¤º¸µéÀ» º¯°æÇϰųª Ãß°¡, »èÁ¦ÇÒ ¼ö ÀÖ´Ù.

index.php?act=module&module=gallery&cmd=si&img=[SQL]
index.php?act=module&module=gallery&cmd=editimg&img=[SQL]
index.php?act=module&module=gallery&cmd=ecard&img=[SQL]
index.php?act=module&module=gallery&cmd=moveimg&img=[SQL]
index.php?act=module&module=gallery&cmd=delimg&img=[SQL]
index.php?act=module&module=gallery&cmd=post&cat=[SQL]
index.php?act=module&module=gallery&cmd=sc&op=user&sort_key=[SQL]
index.php?act=module&module=gallery&cmd=sc&op=user&sort_key=date&order_key=[SQL]
index.php?act=module&module=gallery&cmd=favs&op=add&img=[SQL]
index.php?act=module&module=gallery&cmd=slideshow&cat=[SQL]
index.php?act=module&module=gallery&cmd=user&user=[SQL]&op=view_album&album=1
index.php?act=module&module=gallery&cmd=user&user=[SQL]
index.php?act=module&module=gallery&cmd=user&user=1&op=view_album&album=[SQL]

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2004-03/0210.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Invision Gallery 1.0.1
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ ´ÙÀ½ »çÀÌÆ®¸¦ Âü°íÇÏ¿© ÃֽйöÀüÀÇ Invision Gallery·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù.
http://www.invisionpower.com/products/gallery/
°ü·Ã URL CVE-2004-1835 (CVE)
°ü·Ã URL 9944 (SecurityFocus)
°ü·Ã URL 15566 (ISS)