English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21414
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç Blog Torrent ÇÁ·Î±×·¥¿¡´Â 'btdownload.php' »óÀÇ µð·ºÅ丮 Ž»ö Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
Blog Torrent ´Â Unix °è¿­ ¿î¿µÃ¼Á¦ÀÇ PHP À¥ »çÀÌÆ®¸¦ À§ÇÑ bittorrent ÆÄÀÏ °øÀ¯ ÇÁ·Î±×·¥ÀÌ´Ù. Blog Torrent Preview 0.8 ¹öÀüÀº »ç¿ëÀÚ ÀԷ¿¡ ´ëÇÑ ÀûÀýÇÑ ÇÊÅ͸µÀÌ ¼öÇàµÇÁö ¸øÇÏ¿©, ¿ø°ÝÁö °ø°ÝÀÚµéÀÌ ½Ã½ºÅÛ »óÀÇ ÀÓÀÇÀÇ µð·ºÅ丮µéÀ» Ž»öÇÒ ¼ö ÀÖµµ·Ï Çã¿ëÇÑ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº 'file' ÆÄ¶ó¹ÌÅÍ¿¡ ¾ÇÀÇÀûÀÎ µ¥ÀÌÅ͸¦ Æ÷ÇÔÇÏ¿© Àß Á¶ÀÛÇÑ URL ¿äûÀ» 'btdownload.php' ½ºÅ©¸³Æ®¿¡ Àü´ÞÇÏ´Â ¹æ¹ýÀ¸·Î, ´ë»ó À¥ ¼­¹öÀÇ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ ÆÄÀÏÀ» º¸°Å³ª µð·ºÅ丮µéÀ» Ž»öÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://securitytracker.com/alerts/2004/Dec/1012390.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Blog Torrent Preview 0.8 ¹öÀü
Unix ¸ðµç ¹öÀüµé
ÇØ°áÃ¥ ´ÙÀ½ Blog Torrent CVS Repository À¥ »çÀÌÆ®·ÎºÎÅÍ Blog TorrentÀÇ °¡Àå ÃֽйöÀü(¹öÀü 1.7, 2004³â 12¿ù 1ÀÏ ¼ö¿äÀÏ 01:06:56 2004 UTC ¶Ç´Â ±× ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://cvs.sourceforge.net/viewcvs.py/battletorrent/btorrent_server/btdownload.php?r1=1.6&r2=1.7
°ü·Ã URL CVE-2004-1212 (CVE)
°ü·Ã URL 11795 (SecurityFocus)
°ü·Ã URL 18356 (ISS)