Ãë¾àÁ¡ID |
21462 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç vBulletin ¼ÒÇÁÆ®¿þ¾î¿¡´Â "Last 10 Posts" ½ºÅ©¸³Æ®¿¡ SQL Injection Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. vBulletinÀº Jelsoft Enterprises¿¡¼ °³¹ßÇÑ PHP ±â¹ÝÀÇ À¥ Æ÷·³À¸·Î¼, MySQL µ¥ÀÌÅͺ£À̽º¸¦ »ç¿ëÇÑ´Ù. vBulletinÀ» À§ÇÑ ºñ°ø½Ä Ç÷¯±×ÀÎÀÎ last10.php´Â »ç¿ëÀÚµéÀÌ ÀÚ½ÅÀÇ Æ÷·³(forum) Áß ¸¶Áö¸· 10°³ ÈÁ¦(topic)µéÀ» º¸¿© Áִ ȸÀüÇϴ ǥ½Ã±â(ticker)¿¡ Ãß°¡ÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. Last 10 Posts 2.0.1 ÀÌÇÏÀÇ ¹öÀüµéÀº »ç¿ëÀÚ ÀÔ·Â URI µ¥ÀÌÅͰ¡ SQL Äõ¸®¹®¿¡ »ç¿ëµÇ±â Àü, ¿Ã¹Ù¸¥ ÇÊÅ͸µÀÌ ÀÌ·ç¾îÁöÁö ¾Ê¾Æ SQL Injection °ø°Ý¿¡ Ãë¾àÇÏ´Ù. '$fsel' ±×¸®°í '$ftitle' Àμö¿¡ ³»Àå SQL ¸í·ÉµéÀ» Æ÷ÇÔÇÑ Àß Á¶ÀÛµÈ ¿äûÀ» 'last10.php' ½ºÅ©¸³Æ®·Î º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â µ¥ÀÌÅͺ£À̽ºÀÇ Áß¿äÇÑ Á¤º¸¸¦ ȹµæÇϰųª µ¥ÀÌÅͺ£À̽º »óÀÇ µ¥ÀÌÅ͸¦ »èÁ¦, º¯Á¶, Ãß°¡ÇÒ ¼ö ÀÖ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Jelsoft Enterprises Limited, Last 10 Posts for vBulletin ¹öÀü 2.0.1 ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
2014³â 6¿ù ÇöÀç ¾÷±×·¹À̵峪 ÆÐÄ¡´Â ³ª¿Í ÀÖÁö ¾Ê´Ù.
vBulletinÀÇ ´Ù¿î·Îµå ÆäÀÌÁöÀÎ http://www.vbulletin.com/download.php ¿¡¼ »õ·Ó°Ô ¼öÁ¤µÈ ¹öÀüÀÌ ´Ù¿î·Îµå °¡´ÉÇÒ ¶§ vBulletinÀÇ ¼öÁ¤µÈ ¹öÀüÀ» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2004-1515 (CVE) |
°ü·Ã URL |
11825 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|