Ãë¾àÁ¡ID |
21346 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç À¥ ¼¹ö¿¡ ¼³Ä¡µÇ¾î ÀÖ´Â phpMyFAQ ÇÁ·Î±×·¥ ¹öÀü¿¡ µû¸£¸é, phpMyFAQ ÇÁ·Î±×·¥¿¡´Â ÆÄÀÏ Æ÷ÇÔ(Inclusion) Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. phpMyFAQ´Â Microsoft Windows ¿î¿µÃ¼Á¦ »ó¿¡¼ ¿î¿µµÇ´Â ¹«·á·Î »ç¿ë °¡´ÉÇÑ FAQ ÇÁ·Î±×·¥À¸·Î¼, MySQL µ¥ÀÌÅͺ£À̽º¸¦ »ç¿ëÇÑ´Ù. phpMyFAQ ¹öÀü 1.3.12¿Í 1.4.0-alpha1¿¡´Â ÆÄÀÏ Æ÷ÇÔ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÏ´Â µ¥, ÀÌ´Â 'action' ÆÄ¶ó¹ÌÅ͸¦ ÅëÇØ ÀԷµǴ »ç¿ë µ¥ÀÌÅͰ¡ ÀûÀýÈ÷ ÇÊÅ͸µ µÇÁö ¸øÇÏ´Â µ¥ ±× ¿øÀÎÀÌ ÀÖ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº '\0' ¹®ÀÚ¿ ¸¶Ä§Ç¥½Ã¿Í »ó´ë°æ·Î¸¦ Á¶ÇÕÇÏ¿©, ½Ã½ºÅÛ »óÀÇ ÀÓÀÇÀÇ ÆÄÀÏÀ» º¼ ¼ö ÀÖÀ¸¸ç, °æ¿ì¿¡ µû¶ó Àß ¾Ë·ÁÁø ÆÄÀÏ¿¡ PHP Äڵ带 »ðÀÔÇÒ ¼ö ÀÖ´Ù¸é ÀÓÀÇÀÇ PHP ÄÚµå ½ÇÇ൵ °¡´ÉÇÏ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç phpMyFAQ ÇÁ·Î±×·¥ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0906.html http://www.osvdb.org/show/osvdb/6300
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Thorsten Rinne, phpMyFAQ 1.3.12 ÀÌÇÏ Thorsten Rinne, phpMyFAQ 1.4.0-alpha1 ÀÌÇÏ Microsoft Windows Any version |
ÇØ°áÃ¥ |
phpMyFAQ ´Ù¿î·Îµå »çÀÌÆ®ÀÎ http://www.phpmyfaq.de/download.php ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â phpMyFAQÀÇ °¡Àå ÃֽйöÀü(1.3.13 ¶Ç´Â 1.4.0 alpha2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2004-2255 (CVE) |
°ü·Ã URL |
10374 (SecurityFocus) |
°ü·Ã URL |
16177 (ISS) |
|