Ãë¾àÁ¡ID |
21382 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç Serendipity ½Ã½ºÅÛÀº SQL Injection Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Serendipity´Â PHP·Î Á¦ÀÛµÈ À¥ ºí·Î±× ½Ã½ºÅÛÀÌ´Ù. Serendipity 0.7-beta1 ¿Í ±× ÀÌÀü ¹öÀüµéÀº 'exit.php' and 'comment.php' ½ºÅ©¸³Æ® »ó¿¡¼ 'entry_id' ÆÄ¶ó¹ÌÅÍ¿¡ Àü´ÞµÇ´Â »ç¿ëÀÚ ÀÔ·ÂÀ» ÀûÀýÈ÷ °Ë»çÇÏÁö ¸øÇÏ¿©, SQL Injection Ãë¾àÁ¡ÀÌ ¹ß»ýÇÒ ¼ö ÀÖ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº SQL ¸í·ÉÀÌ Æ÷ÇÔµÈ Àß Á¶ÀÛµÈ ÆÄ¶ó¹ÌÅ͸¦ ¼¹ö¿¡ Àü´ÞÇÏ´Â ¹æ¹ýÀ¸·Î, ÈÄÀ§ µ¥ÀÌÅͺ£À̽º »óÀÇ µ¥ÀÌÅ͸¦ ¼öÁ¤, Ãß°¡, »èÁ¦ÇÏ´Â °ÍÀ» Æ÷ÇÔÇØ¼ »ðÀÔµÈ SQL ¸í·ÉÀÌ ´ë»ó ½Ã½ºÅÛ¿¡¼ ½ÇÇàµÇµµ·Ï ¸¸µé ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://packetstormsecurity.org/0410-exploits/serendipityPoC.txt http://www.osvdb.org/10371 http://securitytracker.com/alerts/2004/Sep/1011448.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: s9y, Serendipity 0.7-beta1 ¿Í ±× ÀÌÀü ¹öÀü ¸ðµç ¿î¿µÃ¼Á¦ÀÇ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
´ÙÀ½ SourceForge.net À¥ »çÀÌÆ®·ÎºÎÅÍ ÇØ´ç Ãë¾àÁ¡ÀÌ ÇØ°áµÈ °¡Àå ÃÖ½ÅÀÇ Serendipity ¹öÀü(0.7-beta3 ¶Ç´Â ±× ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://prdownloads.sourceforge.net/php-blog/serendipity-0.7-beta3.tar.gz?download |
°ü·Ã URL |
CVE-2004-2158 (CVE) |
°ü·Ã URL |
11269 (SecurityFocus) |
°ü·Ã URL |
17533 (ISS) |
|