English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21359
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥ ¼­¹ö »ó¿¡ ¼³Ä¡µÈ vBulletinÀº 'calendar.php' °ü·Ã SQL Injection Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
vBulletinÀº Jelsoft Enterprises¿¡¼­ °³¹ßÇÑ PHP ±â¹ÝÀÇ À¥ Æ÷·³À¸·Î¼­, MySQL µ¥ÀÌÅͺ£À̽º¸¦ »ç¿ëÇÑ´Ù. vBulletin ¹öÀü 2.3.4 ÀÌÀüÀÇ 2.3.x ¹öÀüµé¿¡´Â 'calendar.php' ½ºÅ©¸³Æ® °ü·Ã SQL Injection Ãë¾àÁ¡ÀÌ ¹ß»ýÇÒ ¼ö ÀÖ´Ù. ÀÌ´Â ¾ÖÇø®ÄÉÀ̼ÇÀÌ »ç¿ëÀÚ ÀÔ·Â URI¸¦ ÀûÀýÈ÷ ÇÊÅ͸µÇÏÁö ¸øÇÏ´Â µ¥ ±× ¿øÀÎÀÌ ÀÖ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº 'calendar.php' ½ºÅ©¸³Æ®¿¡ ÀÓÀÇÀÇ SQL Äڵ带 »ðÀÔÇÏ´Â ¹æ¹ýÀ¸·Î, ÈÄÀ§¿¡ À§Ä¡ÇÑ µ¥ÀÌÅͺ£À̽º·ÎºÎÅÍ Áß¿äÇÑ Á¤º¸¸¦ ȹµæÇϰųª µ¥ÀÌÅ͸¦ Ãß°¡, º¯Á¶, »èÁ¦ÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2004-01/0027.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Jelsoft Enterprises Limited, vBulletin 2.3.xx ÀÌÇÏ ¹öÀüµé
Linux Any version
Microsoft Windows Any version
Unix Any version
ÇØ°áÃ¥ ´ÙÀ½ vBulletin ´Ù¿î·Îµå À¥ ÆäÀÌÁö¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â vBulletinÀÇ °¡Àå ÃֽйöÀü(3.0.3 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.vbulletin.com/download.php
°ü·Ã URL CVE-2004-0036 (CVE)
°ü·Ã URL 9360 (SecurityFocus)
°ü·Ã URL 14144 (ISS)