Ãë¾àÁ¡ID |
21313 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç CuteNews ¼ÒÇÁÆ®¿þ¾î¿¡´Â Debug Äõ¸® Á¤º¸ ³ëÃâ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. CuteNews´Â µ¥ÀÌÅͺ£À̽º·ÎÀÇ ÀúÀå ÇüÅ·Π°³º° ÆÄÀϵéÀ» »ç¿ëÇÏ´Â PHP ±â¹ÝÀÇ ´º½º °ü¸® ¼ÒÇÁÆ®¿þ¾î·Î¼ ¹«·á·Î »ç¿ë °¡´ÉÇÏ´Ù. CuteNews ¹öÀü 1.3.1 ½Ã½ºÅÛ¿¡´Â Áß¿äÇÑ ¼¹ö ¼³Á¤ Á¤º¸µéÀ» ¿ø°ÝÁö °ø°ÝÀڵ鿡°Ô ³ëÃâÇÏ´Â Ãë¾àÁ¡À» °®´Â´Ù. ÀÌ´Â CuteNews ½Ã½ºÅÛÀÌ "debug" ¶ó´Â ÆÄ¶ó¹ÌÅ͸¦ °¡Áø "index.php" ÆÄÀÏ ¿äû¿¡ ´ëÇØ ½Ã½ºÅÛÀÇ Áß¿ä Á¤º¸¸¦ ¹ÝÈ¯ÇØ ÁÖ´Â phpinfo()ÇÔ¼ö°¡ ¹Ù·Î ½ÇÇàµÇµµ·Ï ±¸ÇöµÈ ±¸Çö »óÀÇ °áÇÔÀ¸·Î ÀÎÇÏ¿© ¹ß»ýÇÑ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº ´ÙÀ½°ú °°ÀÌ Àß Á¶ÀÛµÈ URLÀ» ½Ã½ºÅÛ¿¡ Àü´ÞÇÔÀ¸·Î½á, ½Ã½ºÅÛ »óÀÇ Áß¿äÇÑ Á¤º¸µéÀ» ȹµæÇÒ ¼ö ÀÖ´Ù. ÀÌ´Â ´ë»ó ½Ã½ºÅÛ¿¡ ´ëÇØ º¸´Ù Áö´ÉÀûÀÎ °ø°ÝµéÀ» ¼öÇàÇÏ´Â µ¥ À¯¿ëÇÏ°Ô ¾²ÀÏ ¼ö ÀÖ´Ù.
http://[target_server]/cutenews/index.php?debug
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/bugtraq/2003-11/0355.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: CutePHP CuteNews Any version Microsoft Windows Any version Unix, Linux Any version |
ÇØ°áÃ¥ |
´ÙÀ½ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ÃֽйöÀüÀÇ CuteNews·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù. http://cutephp.com/ |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
9130 (SecurityFocus) |
°ü·Ã URL |
13868 (ISS) |
|