Ãë¾àÁ¡ID |
21411 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç PHPNews¿¡´Â sendtofriend.php ½ºÅ©¸³Æ®¿¡ ÀÖ´Â SQL Injection Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. PhpNews´Â MySQL µ¥ÀÌÅͺ£À̽º¸¦ »ç¿ëÇÏ´Â PHP ±â¹ÝÀÇ ´º½º ÄÁÅÙÆ® °ü¸®ÀÚ ÇÁ·Î±×·¥À¸·Î¼ ¹«·á·Î »ç¿ë °¡´ÉÇÏ´Ù. PHPNews 1.2.3¿Í ±× ÀÌÀü ¹öÀüµéÀº ¾ÖÇø®ÄÉÀ̼ÇÀÌ »ç¿ëÀÚ ÀÔ·ÂÀ» SQL Äõ¸®¿¡ »ç¿ëÇϱâ Àü, ¿Ã¹Ù¸£°Ô ÇÊÅ͸µÇÏÁö ¸øÇÏ¿© SQL Injection °ø°Ý¿¡ Ãë¾àÇÒ ¼ö ÀÖ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº 'sendtofriend.php' ¸ðµâÀÇ 'mid' º¯¼ö¿¡ ¾ÇÀÇÀûÀÎ SQL ¸í·ÉÀ» Àü´ÞÇÏ´Â ¹æ¹ýÀ¸·Î, ½Ã½ºÅÛÀÇ Á¤º¸¸¦ ȹµæÇϰųª ÈÄÀ§ µ¥ÀÌÅͺ£À̽º »óÀÇ µ¥ÀÌÅ͸¦ Ãß°¡, »èÁ¦, º¯Á¶ÇÒ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.osvdb.org/12119 http://secunia.com/advisories/13300/
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: PHPNews 1.2.3 and prior Microsoft Windows Any version Linux Any version Unix Any version |
ÇØ°áÃ¥ |
´ÙÀ½ PHPNews À¥ »çÀÌÆ®·ÎºÎÅÍ PHPNews °¡Àå ÃֽйöÀü(1.2.3 ¶Ç´Â ±× ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://sourceforge.net/projects/newsphp/ |
°ü·Ã URL |
CVE-2004-2474 (CVE) |
°ü·Ã URL |
11748 (SecurityFocus) |
°ü·Ã URL |
18233 (ISS) |
|