English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21495
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç PostNuke ¼ÒÇÁÆ®¿þ¾î´Â ´ÙÁßÀÇ ½ºÅ©¸³Æ®µé¿¡ ÀÖ´Â ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. Francisco Burzi ¿¡ ÀÇÇØ °³¹ßµÈ PostNuke´Â ¹«·á·Î »ç¿ë °¡´ÉÇÑ °ø°³ ¼Ò½º PHP ±â¹ÝÀÇ ÄÁÅÙÃ÷ °ü¸® ½Ã½ºÅÛ (CMS)ÀÌ´Ù. PostNuke 0.760RC2 ÀÌÇÏÀÇ ¹öÀüµéÀº pnadmin.php, past.php, admin.php, dl-util.php, dl-search.php ±×¸®°í index.php ½ºÅ©¸³Æ®µé¿¡ ÀÖ´Â SQL ÁÖÀÔ, Cross-Site Scripting Ãë¾àÁ¡µé, ±×¸®°í °æ·Î¸í ³ëÃâ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. SQL ÁÖÀÔ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ PostNuke¿¡ ÀÇÇØ »ç¿ëµÇ´Â µ¥ÀÌÅͺ£À̽º¿¡ »ç¿ëÀÚ Á¤º¸¸¦ Ãß°¡, ¼öÁ¤, ȤÀº »èÁ¦ÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. Cross-Site Scripting Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ÄíŰ ±â¹ÝÀÇ ÀÎÁõ ½Å¿ëÁ¤º¸¸¦ »©³»°Å³ª ´Ù¸¥ °ø°ÝµéÀÇ ¼öÇàÀ» Çã¿ëÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2005-02/0471.html
http://archives.neohapsis.com/archives/bugtraq/2005-02/0472.html
http://archives.neohapsis.com/archives/bugtraq/2005-02/0473.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Francisco Burzi, PostNuke 0.760RC2 ÀÌÇÏÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ PostNuke´Â ´õ ÀÌ»ó Áö¿øµÇÁö ¾Ê´Â´Ù. ´Ù¸¥ ¼Ö·ç¼ÇÀ¸·Î ´ëüÇÒ °ÍÀ» ±Ç°íÇÑ´Ù.
°ü·Ã URL CVE-2005-0615,CVE-2005-0617 (CVE)
°ü·Ã URL 12683,12684,12685 (SecurityFocus)
°ü·Ã URL 19525 (ISS)