English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21325
À§Çèµµ 20
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥¼­¹ö¿¡ ¼³Ä¡µÈ PowerPortal¿¡´Â °æ·Î ³ëÃâ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
PowerPortalÀº PHP·Î Á¦ÀÛµÈ À¯´Ð½º ±â¹ÝÀÇ ÄÁÅÙÆ® °ü¸® ½Ã½ºÅÛÀÌ´Ù. PowerPortal ¹öÀü 1.x ½Ã½ºÅÛ¿¡´Â À¥ ·çÆ® µð·ºÅ丮 °æ·Î ³ëÃâ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº ´ÙÀ½°ú °°Àº URLÀ» Àü´ÞÇÏ´Â ¹æ¹ýÀ¸·Î,

http://[target_server]modules/gallery/resize.php
http://[target_server]/power/modules.php?name=gallery&files=darkbicho

PowerPortalÀÌ À¥ ·çÆ® µð·ºÅ丮ÀÇ Àüü °æ·Î¸¦ Æ÷ÇÔÇÏ´Â ¿¡·¯ ¸Þ½ÃÁö¸¦ ¹ÝȯÇϵµ·Ï ¸¸µé ¼ö ÀÖ´Ù. À̸¦ ÅëÇØ ȹµæµÈ Á¤º¸´Â ¿ø°ÝÁö °ø°ÝÀÚµéÀÌ º¸´Ù Áö´ÉÀûÀÎ °ø°ÝÀ» ¼öÇàÇÏ´Â µ¥ À¯¿ëÇÏ°Ô »ç¿ëµÉ ¼ö ÀÖ´Ù

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0905.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
PowerPortal 1.x
Unix Any version
ÇØ°áÃ¥ 2014³â 6¿ù ÇöÀç ¾÷±×·¹À̵峪 ÆÐÄ¡´Â ³ª¿Í ÀÖÁö ¾Ê´Ù. Ãë¾àÁ¡¿¡ ´ëÇØ Á¦Ç°ÀÇ Á¦Á¶»ç¿¡ ¹®ÀÇÇÑ´Ù.
°ü·Ã URL CVE-2004-0662 (CVE)
°ü·Ã URL 10622 (SecurityFocus)
°ü·Ã URL 16529 (ISS)