English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21313
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç CuteNews ¼ÒÇÁÆ®¿þ¾î¿¡´Â Debug Äõ¸® Á¤º¸ ³ëÃâ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. CuteNews´Â µ¥ÀÌÅͺ£À̽º·ÎÀÇ ÀúÀå ÇüÅ·Π°³º° ÆÄÀϵéÀ» »ç¿ëÇÏ´Â PHP ±â¹ÝÀÇ ´º½º °ü¸® ¼ÒÇÁÆ®¿þ¾î·Î¼­ ¹«·á·Î »ç¿ë °¡´ÉÇÏ´Ù. CuteNews ¹öÀü 1.3.1 ½Ã½ºÅÛ¿¡´Â Áß¿äÇÑ ¼­¹ö ¼³Á¤ Á¤º¸µéÀ» ¿ø°ÝÁö °ø°ÝÀڵ鿡°Ô ³ëÃâÇÏ´Â Ãë¾àÁ¡À» °®´Â´Ù. ÀÌ´Â CuteNews ½Ã½ºÅÛÀÌ "debug" ¶ó´Â ÆÄ¶ó¹ÌÅ͸¦ °¡Áø "index.php" ÆÄÀÏ ¿äû¿¡ ´ëÇØ ½Ã½ºÅÛÀÇ Áß¿ä Á¤º¸¸¦ ¹ÝÈ¯ÇØ ÁÖ´Â phpinfo()ÇÔ¼ö°¡ ¹Ù·Î ½ÇÇàµÇµµ·Ï ±¸ÇöµÈ ±¸Çö »óÀÇ °áÇÔÀ¸·Î ÀÎÇÏ¿© ¹ß»ýÇÑ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº ´ÙÀ½°ú °°ÀÌ Àß Á¶ÀÛµÈ URLÀ» ½Ã½ºÅÛ¿¡ Àü´ÞÇÔÀ¸·Î½á, ½Ã½ºÅÛ »óÀÇ Áß¿äÇÑ Á¤º¸µéÀ» ȹµæÇÒ ¼ö ÀÖ´Ù. ÀÌ´Â ´ë»ó ½Ã½ºÅÛ¿¡ ´ëÇØ º¸´Ù Áö´ÉÀûÀÎ °ø°ÝµéÀ» ¼öÇàÇÏ´Â µ¥ À¯¿ëÇÏ°Ô ¾²ÀÏ ¼ö ÀÖ´Ù.

http://[target_server]/cutenews/index.php?debug

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2003-11/0355.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
CutePHP CuteNews Any version
Microsoft Windows Any version
Unix, Linux Any version
ÇØ°áÃ¥ ´ÙÀ½ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ÃֽйöÀüÀÇ CuteNews·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù.
http://cutephp.com/
°ü·Ã URL (CVE)
°ü·Ã URL 9130 (SecurityFocus)
°ü·Ã URL 13868 (ISS)