English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21374
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç WordPress ÇÁ·Î±×·¥Àº SQL Injection Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
WordPress ´Â MySQL µ¥ÀÌÅͺ£À̽º¸¦ »ç¿ëÇÏ´Â PHP ±â¹ÝÀÇ ÃâÆÇ(publication) ÇÁ·Î±×·¥À¸·Î¼­, ¹«·á·Î »ç¿ë °¡´ÉÇÑ ÇÁ·Î±×·¥ÀÌ´Ù. ÀÌ WordPress ¹öÀü 0.7 ¿¡´Â 'posts' º¯¼ö¿¡ Àü´ÞµÇ´Â »ç¿ëÀÚ ÀÔ·ÂÀ» ¿Ã¹Ù¸£°Ô ÇÊÅ͸µÇÏÁö ¸øÇÏ¿© SQL Injection Ãë¾àÁ¡ÀÌ ¹ß»ýÇÒ ¼ö ÀÖ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº SQL Äڵ带 Æ÷ÇÔÇÏ´Â Àß Á¶ÀÛµÈ ¿äûÀ» Àü´ÞÇÔÀ¸·Î½á, ÈÄÀ§ µ¥ÀÌÅͺ£À̽º ¼­¹ö·Î ÇÏ¿©±Ý »ðÀÔµÈ SQL Äڵ带 ½ÇÇàÇϵµ·Ï ¸¸µé ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://securitytracker.com/alerts/2003/Jun/1006937.html
http://www.osvdb.org/4610

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Matthew Mullenweg, WordPress 0.7
Microsoft Windows Any version
Unix Any version
Linux Any version
ÇØ°áÃ¥ ´ÙÀ½ WordPress ´Ù¿î·Îµå À¥ ÆäÀÌÁö http://wordpress.org/download/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â ÀÌ Ãë¾àÁ¡À» ÇØ°áÇÑ WordPress ¹öÀü(0.72 RC1 ¶Ç´Â ±× ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL 7784 (SecurityFocus)
°ü·Ã URL 12204 (ISS)