Ãë¾àÁ¡ID |
21403 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç Invision Power Board¿¡´Â 'Arcade' Action °ü·Ã SQL Injection Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Invision Power Board ´Â Invision Power Services »ç¿¡¼ ¹èÆ÷ÇÏ´Â PHP ±â¹ÝÀÇ À¥ Æ÷·³(forum) ¼ÒÇÁÆ®¿þ¾î ÆÐŰÁöÀÌ´Ù. ÀϺΠibProArcade ¸ðµâÀÌ µ¿ÀÛÇÏ´Â Invision Power Board ½Ã½ºÅÛµéÀº SQL Injection °ø°Ý¿¡ ¿µÇâÀ» ¹ÞÀ» ¼ö ÀÖ´Ù. ÀÌ´Â ¾ÖÇø®ÄÉÀ̼ÇÀÌ SQL Äõ¸®¹®¿¡ »ç¿ëµÇ´Â 'category' ÇʵåÀÇ »ç¿ëÀÚ ÀÔ·Â µ¥ÀÌÅ͸¦ ÀûÀýÈ÷ °Ë»çÇÏÁö ¸øÇÏ´Â µ¥ ±× ¿øÀÎÀÌ ÀÖ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº ¾ÇÀÇÀûÀÎ SQL ¸í·ÉÀ» 'category' Çʵ忡 ³Ñ±â´Â ¹æ¹ýÀ¸·Î, ÈÄÀ§ µ¥ÀÌÅͺ£À̽º »óÀÇ µ¥ÀÌÅ͸¦ Ãß°¡, »èÁ¦, ¼öÁ¤ÇÏ´Â ÇàÀ§¸¦ Æ÷ÇÔÇØ¼ ÀÓÀÇÀÇ ¸í·ÉÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securitytracker.com/alerts/2004/Nov/1012292.html http://archives.neohapsis.com/archives/bugtraq/2004-11/0264.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: ibProArcade 2.5¿Í °¡´ÉÇÑ ¸ðµç ¹öÀü Microsoft Windows ¸ðµç ¹öÀü Unix ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
2014³â 6¿ù ÇöÀç ¾÷±×·¹À̵峪 ÆÐÄ¡´Â ³ª¿Í ÀÖÁö ¾Ê´Ù.
ibProArcade À¥ »çÀÌÆ®ÀÎ http://www.ibparcade.com/ ¿¡¼ ¹®Á¦°¡ ÇØ°áµÈ »õ ¹öÀüÀÌ ´Ù¿î·Îµå °¡´ÉÇÒ ¶§ ibProArcadeÀÇ »õ ¹öÀüÀ» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2004-1536 (CVE) |
°ü·Ã URL |
11719 (SecurityFocus) |
°ü·Ã URL |
18180 (ISS) |
|