English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21519
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç Hosting Controller´Â ´ÙÁßÀÇ Á¤º¸ ³ëÃâ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. Hosting Controller´Â ÇϳªÀÇ ÀÎÅÍÆäÀ̽º¸¦ ÅëÇØ ¸ðµç È£½ºÆÃ ¾÷¹«µéÀ» ÅëÇÕ °ü¸®ÇÒ ¼ö ÀÖ´Â Microsoft Windows ¿î¿µÃ¼Á¦µéÀ» À§ÇÑ ¾îÇø®ÄÉÀ̼ÇÀÌ´Ù. Hosting Controller 6.1 Hotfix 1.7 ÀÌÇÏÀÇ ¹öÀüµéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ¿¡°Ô ¹Î°¨ÇÑ Á¤º¸¸¦ ³ëÃâ½ÃÄÑ ÁÙ ¼ö ÀÖ´Ù. ÀÌ Á¤º¸´Â ÄÄÇ»ÅÍ¿¡ ´ëÇÑ Á» ´õ Á¤¹ÐÇÑ °ø°ÝµéÀ» ¼öÇàÇÏ´Â µ¥ »ç¿ëµÉ ¼ö ÀÖ´Ù. ´ÙÀ½ÀÇ Ãë¾àÁ¡µéÀÌ º¸°íµÇ¾î ÀÖ´Ù:

1) ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ $path/logs/HCDiskQuotaService.csv ÆÄÀÏÀ» ´Ù¿î·ÎµåÇÒ ¼ö ÀÖ´Ù. ÀÌ ÆÄÀÏÀº ´ë¿ªÆøÀ̳ª µð½ºÅ© »ç¿ë·®, ±×¸®°í ±âŸ Åë°èÄ¡¿Í °°Àº Á¤º¸¸¦ Æ÷ÇÔÇϰí ÀÖ´Ù. ¶ÇÇÑ ¸ðµç È£½ºÆ®ÇÑ µµ¸ÞÀεéÀÇ µµ¸ÞÀÎ ¸íµµ ÀÌ ÆÄÀÏ¿¡ ´ã°ÜÁ® ÀÖ´Ù.
2) 'forgotpassword.asp' ½ºÅ©¸³Æ®·ÎÀÇ ¸µÅ©¿¡ ´ëÇÑ 'login ID' Àμö¸¦ ÅëÇÏ¿© ´ë»ó µµ¸ÞÀÎ ¸íÀ» Á¦°øÇÔÀ¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ´ë»ó µµ¸ÞÀÎÀÇ °ü¸®ÀÚ email ÁÖ¼Ò¸¦ ¾ò¾î³¾ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securitytracker.com/alerts/2005/Mar/1013395.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
HostingController.com, Hosting Controller 6.1 Hotfix 1.7 ÀÌÇÏÀÇ ¹öÀüµé
Microsoft Windows Any version
ÇØ°áÃ¥ Hosting Controller À¥ »çÀÌÆ®ÀÎ http://www.hostingcontroller.com/english/index.html ¿¡¼­ ÃֽŹöÀüÀÇ Hotfix(2.0ÀÌ»ó)¸¦ ÆÐÄ¡ÇØ¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2005-0695 (CVE)
°ü·Ã URL 12748 (SecurityFocus)
°ü·Ã URL 19637 (ISS)