Ãë¾àÁ¡ID |
21544 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç Mambo Open Source´Â Tar.php ½ºÅ©¸³Æ®¿¡ ÀÖ´Â PHP ¿ø°Ý ÄÚµå ÁÖÀÔ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Mambo Open Source(¿¹Àü¿¡´Â Mambo Site Server·Î ºÒ¸²)´Â ÀÎÅÍ³Ý Æ÷ÅÐ ¹× ÄÜÅÙÃ÷ °ü¸® ¼ÒÇÁÆ®¿þ¾îÀÌ´Ù. Mambo Open Source 4.5.2 ÀÌÇÏÀÇ ¹öÀüµéÀº 'Tar.php' ½ºÅ©¸³Æ®ÀÇ mosConfig_absolute_path Àμö·Î °Ç³×Áø »ç¿ëÀÚ Á¦°ø ÀԷ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ ÇÊÅ͸µÀ¸·Î ÀÎÇÏ¿© Á¦ 3ÀÇ ¼¹ö »ó¿¡¼ È£½ºÆÃÇÏ´Â ¾ÇÀÇÀûÀÎ PHP ÆÄÀϵéÀ» Æ÷ÇÔ(Include)ÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¸¸¾à PHP ¼³Á¤ ÆÄÀÏÀÌ register_globals ¼³Á¤À» 'on'À¸·Î ¼³Á¤Çϰí ÀÖ´Ù¸é ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â Àß Á¶ÀÛµÈ URLÀ» Á¦°øÇÏ¿© À¥ ¼ºñ½ºÀÇ ±ÇÇÑÀ» °¡Áö°í ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡¼ ÀÓÀÇÀÇ PHP Äڵ带 IncludeÇÏ¿© ½ÇÇà½Ãų ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securitytracker.com/alerts/2005/Feb/1013250.html http://www.osvdb.org/14021 http://help.mamboserver.com/index.php?option=com_content&task=view&id=426&Itemid=88
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Miro Construct Pty »ç, Mambo Open Source 4.5.2 ÀÌÇÏÀÇ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
´ÙÀ½ Mamboportal ´Ù¿î·Îµå À¥ ÆäÀÌÁö¿¡¼ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â Mambo Open SourceÀÇ °¡Àå ÃֽйöÀü(4.5.2.1 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. http://sourceforge.net/projects/mambo/ |
°ü·Ã URL |
CVE-2005-0512 (CVE) |
°ü·Ã URL |
12608 (SecurityFocus) |
°ü·Ã URL |
19429 (ISS) |
|