English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21375
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥ ¼­¹ö »ó¿¡ ¼³Ä¡µÈ aspWebAlbum ÇÁ·Î±×·¥Àº SQL Injection Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù.
aspWebAlbum ÇÁ·Î±×·¥Àº MS Windows Ç÷§Æû »ó¿¡¼­ µ¿ÀÛÇÏ´Â »çÁø ¾Ù¹üÀ» Á¦ÀÛÇÏ°í °ü¸®ÇÒ ¼ö ÀÖ´Â À¥ ±â¹ÝÀÇ ÇÁ·Î±×·¥ÀÌ´Ù. ÀÌ aspWebAlbum ¿¡´Â 'album.asp' ½ºÅ©¸³Æ® »ó¿¡¼­ ÀûÀýÇÑ »ç¿ëÀÚ ÀԷ¿¡ ´ëÇÑ °Ë»ç¸¦ ¼öÇàÇÏÁö ¸øÇÏ¿© SQL Injection Ãë¾àÁ¡ÀÌ ¹ß»ýÇÒ ¼ö ÀÖ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº '/album.asp?action=login' ½ºÅ©¸³Æ® ¶Ç´Â 'album.asp' ½ºÅ©¸³Æ®ÀÇ 'cat' Çʵ带 ÅëÇØ¼­ Àß Á¶ÀÛµÈ SQL ¸í·ÉÀ» »ðÀÔÇÏ´Â ¹æ¹ýÀ¸·Î, ´ë»ó ½Ã½ºÅÛ¿¡¼­ SQL ¸í·É ½ÇÇà ¹× Áß¿äÇÑ Á¤º¸µéÀ» ȹµæÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://securitytracker.com/alerts/2004/Sep/1011411.html
http://archives.neohapsis.com/archives/bugtraq/2004-09/0352.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Full Revolution, Inc., aspWebAlbum Any version
Microsoft Windows Any version
ÇØ°áÃ¥ 2014³â 6¿ù ÇöÀç ¾÷±×·¹À̵峪 ÆÐÄ¡´Â ³ª¿Í ÀÖÁö ¾Ê´Ù.

Full Revolution »çÀÇ À¥ »çÀÌÆ®ÀÎ http://www.fullrevolution.com/album_overview.asp ¿¡¼­ ¹®Á¦°¡ ÇØ°áµÈ »õ ¹öÀüÀÌ ´Ù¿î·Îµå °¡´ÉÇÒ ¶§ aspWebAlbumÀÇ »õ ¹öÀüÀ» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2004-1553 (CVE)
°ü·Ã URL 11246 (SecurityFocus)
°ü·Ã URL 17507 (ISS)