Ãë¾àÁ¡ID |
21374 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç WordPress ÇÁ·Î±×·¥Àº SQL Injection Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. WordPress ´Â MySQL µ¥ÀÌÅͺ£À̽º¸¦ »ç¿ëÇÏ´Â PHP ±â¹ÝÀÇ ÃâÆÇ(publication) ÇÁ·Î±×·¥À¸·Î¼, ¹«·á·Î »ç¿ë °¡´ÉÇÑ ÇÁ·Î±×·¥ÀÌ´Ù. ÀÌ WordPress ¹öÀü 0.7 ¿¡´Â 'posts' º¯¼ö¿¡ Àü´ÞµÇ´Â »ç¿ëÀÚ ÀÔ·ÂÀ» ¿Ã¹Ù¸£°Ô ÇÊÅ͸µÇÏÁö ¸øÇÏ¿© SQL Injection Ãë¾àÁ¡ÀÌ ¹ß»ýÇÒ ¼ö ÀÖ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº SQL Äڵ带 Æ÷ÇÔÇÏ´Â Àß Á¶ÀÛµÈ ¿äûÀ» Àü´ÞÇÔÀ¸·Î½á, ÈÄÀ§ µ¥ÀÌÅͺ£À̽º ¼¹ö·Î ÇÏ¿©±Ý »ðÀÔµÈ SQL Äڵ带 ½ÇÇàÇϵµ·Ï ¸¸µé ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://securitytracker.com/alerts/2003/Jun/1006937.html http://www.osvdb.org/4610
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Matthew Mullenweg, WordPress 0.7 Microsoft Windows Any version Unix Any version Linux Any version |
ÇØ°áÃ¥ |
´ÙÀ½ WordPress ´Ù¿î·Îµå À¥ ÆäÀÌÁö http://wordpress.org/download/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â ÀÌ Ãë¾àÁ¡À» ÇØ°áÇÑ WordPress ¹öÀü(0.72 RC1 ¶Ç´Â ±× ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
7784 (SecurityFocus) |
°ü·Ã URL |
12204 (ISS) |
|