English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21320
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥¼­¹ö¿¡ ¼³Ä¡µÈ OpenDocMan ¹öÀü¿¡´Â Á¢±Ù ¿ìȸ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
OpenDocManÀº ¹®¼­ °ü¸®¸¦ À§ÇÑ ISO 17025 ¿Í OIE Ç¥ÁØ¿¡ µû¶ó °³¹ßµÈ À¥ ±â¹ÝÀÇ ¹®¼­ °ü¸® ½Ã½ºÅÛÀÌ´Ù. OpenDocMan¿¡´Â "commitchange.php"ÀÇ ÀÎÁõ °Ë»ç »óÀÇ °áÇÔÀ¸·Î ÀÎÇÏ¿© »ç¿ëÀڵ鿡°Ô Àΰ¡µÇÁö ¾ÊÀº º¯°æ(change)¸¦ Çã¿ëÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿©, ¿ø°ÝÁö °ø°ÝÀÚµéÀº Á¤´çÇÑ ÀÎÁõÀýÂ÷¸¦ ÅëÇÏÁö ¾Ê°íµµ ¾ÖÇø®ÄÉÀ̼ǿ¡ ´ëÇÑ °ü¸®ÀÚ ±ÇÇÑÀ» ȹµæÇÒ ¼ö ÀÖÀ¸¸ç, ÀÌ·Î ÀÎÇÏ¿© ¸ðµç °èÁ¤À» »èÁ¦Çϰųª Á¤´çÇÑ »ç¿ëÀÚµéÀ» Á¢±ÙÀ» °ÅºÎÇÏ´Â µîÀÇ ¾ÇÀÇÀûÀÎ ÇàÀ§¸¦ ÇÒ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç À¥ ¼­¹ö »ó¿¡ ¼³Ä¡µÈ OpenDocMan ÇÁ·Î±×·¥ÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/secunia/2004-q3/0150.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
OpenDocMan 1.0
OpenDocMan 1.1
ÇØ°áÃ¥ ´ÙÀ½ OpenDocMan ´Ù¿î·Îµå ÆäÀÌÁö·ÎºÎÅÍ ¹®Á¦°¡ ÇØ°áµÈ ¹öÀü 1.2-Final À̳ª °¡Àå ÃֽйöÀüÀ» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://prdownloads.sourceforge.net/opendocman/opendocman-1.2.tar.gz?download
°ü·Ã URL (CVE)
°ü·Ã URL 10807 (SecurityFocus)
°ü·Ã URL (ISS)