Ãë¾àÁ¡ID |
21495 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç PostNuke ¼ÒÇÁÆ®¿þ¾î´Â ´ÙÁßÀÇ ½ºÅ©¸³Æ®µé¿¡ ÀÖ´Â ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. Francisco Burzi ¿¡ ÀÇÇØ °³¹ßµÈ PostNuke´Â ¹«·á·Î »ç¿ë °¡´ÉÇÑ °ø°³ ¼Ò½º PHP ±â¹ÝÀÇ ÄÁÅÙÃ÷ °ü¸® ½Ã½ºÅÛ (CMS)ÀÌ´Ù. PostNuke 0.760RC2 ÀÌÇÏÀÇ ¹öÀüµéÀº pnadmin.php, past.php, admin.php, dl-util.php, dl-search.php ±×¸®°í index.php ½ºÅ©¸³Æ®µé¿¡ ÀÖ´Â SQL ÁÖÀÔ, Cross-Site Scripting Ãë¾àÁ¡µé, ±×¸®°í °æ·Î¸í ³ëÃâ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. SQL ÁÖÀÔ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ PostNuke¿¡ ÀÇÇØ »ç¿ëµÇ´Â µ¥ÀÌÅͺ£À̽º¿¡ »ç¿ëÀÚ Á¤º¸¸¦ Ãß°¡, ¼öÁ¤, ȤÀº »èÁ¦ÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. Cross-Site Scripting Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ÄíŰ ±â¹ÝÀÇ ÀÎÁõ ½Å¿ëÁ¤º¸¸¦ »©³»°Å³ª ´Ù¸¥ °ø°ÝµéÀÇ ¼öÇàÀ» Çã¿ëÇÒ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/bugtraq/2005-02/0471.html http://archives.neohapsis.com/archives/bugtraq/2005-02/0472.html http://archives.neohapsis.com/archives/bugtraq/2005-02/0473.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Francisco Burzi, PostNuke 0.760RC2 ÀÌÇÏÀÇ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
PostNuke´Â ´õ ÀÌ»ó Áö¿øµÇÁö ¾Ê´Â´Ù. ´Ù¸¥ ¼Ö·ç¼ÇÀ¸·Î ´ëüÇÒ °ÍÀ» ±Ç°íÇÑ´Ù. |
°ü·Ã URL |
CVE-2005-0615,CVE-2005-0617 (CVE) |
°ü·Ã URL |
12683,12684,12685 (SecurityFocus) |
°ü·Ã URL |
19525 (ISS) |
|