English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21544
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç Mambo Open Source´Â Tar.php ½ºÅ©¸³Æ®¿¡ ÀÖ´Â PHP ¿ø°Ý ÄÚµå ÁÖÀÔ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Mambo Open Source(¿¹Àü¿¡´Â Mambo Site Server·Î ºÒ¸²)´Â ÀÎÅÍ³Ý Æ÷ÅÐ ¹× ÄÜÅÙÃ÷ °ü¸® ¼ÒÇÁÆ®¿þ¾îÀÌ´Ù. Mambo Open Source 4.5.2 ÀÌÇÏÀÇ ¹öÀüµéÀº 'Tar.php' ½ºÅ©¸³Æ®ÀÇ mosConfig_absolute_path Àμö·Î °Ç³×Áø »ç¿ëÀÚ Á¦°ø ÀԷ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ ÇÊÅ͸µÀ¸·Î ÀÎÇÏ¿© Á¦ 3ÀÇ ¼­¹ö »ó¿¡¼­ È£½ºÆÃÇÏ´Â ¾ÇÀÇÀûÀÎ PHP ÆÄÀϵéÀ» Æ÷ÇÔ(Include)ÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¸¸¾à PHP ¼³Á¤ ÆÄÀÏÀÌ register_globals ¼³Á¤À» 'on'À¸·Î ¼³Á¤Çϰí ÀÖ´Ù¸é ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â Àß Á¶ÀÛµÈ URLÀ» Á¦°øÇÏ¿© À¥ ¼­ºñ½ºÀÇ ±ÇÇÑÀ» °¡Áö°í ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡¼­ ÀÓÀÇÀÇ PHP Äڵ带 IncludeÇÏ¿© ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securitytracker.com/alerts/2005/Feb/1013250.html
http://www.osvdb.org/14021
http://help.mamboserver.com/index.php?option=com_content&task=view&id=426&Itemid=88

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Miro Construct Pty »ç, Mambo Open Source 4.5.2 ÀÌÇÏÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ ´ÙÀ½ Mamboportal ´Ù¿î·Îµå À¥ ÆäÀÌÁö¿¡¼­ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â Mambo Open SourceÀÇ °¡Àå ÃֽйöÀü(4.5.2.1 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
http://sourceforge.net/projects/mambo/
°ü·Ã URL CVE-2005-0512 (CVE)
°ü·Ã URL 12608 (SecurityFocus)
°ü·Ã URL 19429 (ISS)