English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21411
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç PHPNews¿¡´Â sendtofriend.php ½ºÅ©¸³Æ®¿¡ ÀÖ´Â SQL Injection Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
PhpNews´Â MySQL µ¥ÀÌÅͺ£À̽º¸¦ »ç¿ëÇÏ´Â PHP ±â¹ÝÀÇ ´º½º ÄÁÅÙÆ® °ü¸®ÀÚ ÇÁ·Î±×·¥À¸·Î¼­ ¹«·á·Î »ç¿ë °¡´ÉÇÏ´Ù. PHPNews 1.2.3¿Í ±× ÀÌÀü ¹öÀüµéÀº ¾ÖÇø®ÄÉÀ̼ÇÀÌ »ç¿ëÀÚ ÀÔ·ÂÀ» SQL Äõ¸®¿¡ »ç¿ëÇϱâ Àü, ¿Ã¹Ù¸£°Ô ÇÊÅ͸µÇÏÁö ¸øÇÏ¿© SQL Injection °ø°Ý¿¡ Ãë¾àÇÒ ¼ö ÀÖ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº 'sendtofriend.php' ¸ðµâÀÇ 'mid' º¯¼ö¿¡ ¾ÇÀÇÀûÀÎ SQL ¸í·ÉÀ» Àü´ÞÇÏ´Â ¹æ¹ýÀ¸·Î, ½Ã½ºÅÛÀÇ Á¤º¸¸¦ ȹµæÇϰųª ÈÄÀ§ µ¥ÀÌÅͺ£À̽º »óÀÇ µ¥ÀÌÅ͸¦ Ãß°¡, »èÁ¦, º¯Á¶ÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.osvdb.org/12119
http://secunia.com/advisories/13300/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
PHPNews 1.2.3 and prior
Microsoft Windows Any version
Linux Any version
Unix Any version
ÇØ°áÃ¥ ´ÙÀ½ PHPNews À¥ »çÀÌÆ®·ÎºÎÅÍ PHPNews °¡Àå ÃֽйöÀü(1.2.3 ¶Ç´Â ±× ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://sourceforge.net/projects/newsphp/
°ü·Ã URL CVE-2004-2474 (CVE)
°ü·Ã URL 11748 (SecurityFocus)
°ü·Ã URL 18233 (ISS)