English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21318
À§Çèµµ 20
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥¼­¹ö¿¡ ¼³Ä¡µÈ phpBB´Â ´Ù¼öÀÇ °æ·Î ³ëÃâ Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. .
phpBB´Â °Ô½ÃÆÇ(bulletin board)À» À§ÇÑ ¿ÀÇ ¼Ò½º ¼ÒÇÁÆ®¿þ¾î ÆÐŰÁö·Î¼­, µ¥ÀÌÅͺ£À̽º·Î´Â MySQL, MS-SQL, PostgreSQL, Access/ODBC µîÀ» »ç¿ëÇÑ´Ù. phpBB ¹öÀü 2.0.8°ú ±× ÀÌÀü ¹öÀüÀÇ °æ¿ì,
'index.php', 'lang_faq.php', 'lang_bbcode.php', 'lusercp_viewprofile.php' ½ºÅ©¸³Æ®µé »ó¿¡ ´Ù¼öÀÇ °æ·Î ³ëÃâ Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº Àß Á¶ÀÛµÈ URLÀ» ÀÌ Ãë¾àÇÑ ½ºÅ©¸³Æ®µé¿¡ Àü´ÞÇÏ´Â ¹æ¹ýÀ¸·Î, phpBB°¡ À¥ ·çÆ® µð·ºÅ丮ÀÇ Àüü °æ·Î¸¦ Æ÷ÇÔÇÏ´Â ¿¡·¯ ¸Þ½ÃÁö¸¦ ¹ÝȯÇϵµ·Ï ¸¸µé ¼ö ÀÖ´Ù. À̸¦ ÅëÇØ ȹµæµÈ Á¤º¸´Â ¿ø°ÝÁö °ø°ÝÀÚµéÀÌ º¸´Ù Áö´ÉÀûÀÎ °ø°ÝÀ» ¼öÇàÇÏ´Â µ¥ À¯¿ëÇÏ°Ô »ç¿ëµÉ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2004-07/0170.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
phpBB 2.0.8
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ ´ÙÀ½ÀÇ phpBB ´Ù¿î·Îµå À¥ ÆäÀÌÁö¸¦ ÂüÁ¶ÇÏ¿© phpBBÀÇ °¡Àå ÃֽйöÀü(2.0.10 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.phpbb.com/downloads.php
°ü·Ã URL CVE-2004-0729 (CVE)
°ü·Ã URL 10738 (SecurityFocus)
°ü·Ã URL 16716,16720,16722,16723 (ISS)