Ãë¾àÁ¡ID |
21517 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
paFileDBÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ÇØ´ç ÇÁ·Î±×·¥¿¡´Â ÆÐ½º¿öµå ÇØ½¬(Hash) ³ëÃâ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. paFileDB´Â MySQL µ¥ÀÌÅͺ£À̽º¸¦ »ç¿ëÇÏ´Â PHP Arena¿¡ ÀÇÇØ °³¹ßµÈ À¥ ±â¹ÝÀÇ ÆÄÀÏ ´Ù¿î·Îµå °ü¸® ÇÁ·Î±×·¥ÀÌ´Ù. paFileDB 3.1 ÀÌÇÏÀÇ ¹öÀüµéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ °ü¸®ÀÚ¸¦ Æ÷ÇÔÇÏ¿© ´Ù¸¥ °èÁ¤µéÀÇ ÆÐ½º¿öµå ÇØ½¬¸¦ º¼ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¸¸¾à °ü¸®ÀÚ°¡ ½Ã½ºÅÛ¿¡ ÇöÀç ·Î±×¿ÂÇØ ÀÖ´Ù¸é ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â sessions µð·ºÅ丮¸¦ ¾×¼¼½ºÇÏ¿© °ü¸®ÀÚÀÇ ÇØ½¬ÈµÈ ÆÐ½º¿öµå¸¦ º¼ ¼ö ÀÖ´Ù. ÀÌ ¹®Á¦´Â Cookie ÀÎÁõÀÌ ¾Æ´Ñ Session ÀÎÁõÀÌ »ç¿ëµÇ°í ÀÖÀ» ¶§¿¡¸¸ Á¸ÀçÇÑ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç À¥ ¼¹ö »ó¿¡ ¼³Ä¡µÈ paFileDB ÇÁ·Î±×·¥ÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securitytracker.com/alerts/2004/Dec/1012421.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: PHP Arena, paFileDB 3.1 ÀÌÇÏÀÇ ¹öÀüµé Linux Any version Microsoft Windows Any version Unix Any version |
ÇØ°áÃ¥ |
paFileDB´Â ´õ ÀÌ»ó Áö¿øµÇÁö ¾Ê´Â´Ù. º¸¾ÈÀ» À§ÇØ ´Ù¸¥ ¼Ö·ç¼ÇÀ¸·Î ´ëüÇÒ °ÍÀ» ±Ç°íÇÑ´Ù. |
°ü·Ã URL |
CVE-2004-1219 (CVE) |
°ü·Ã URL |
11818 (SecurityFocus) |
°ü·Ã URL |
18364 (ISS) |
|