English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 210059
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç XOOPS ÇÁ·Î±×·¥Àº 'spaw_root' Àμö¸¦ ÅëÇÑ ¿ø°Ý ÆÄÀÏ Æ÷ÇÔ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. XOOPS´Â PHP·Î ÀÛ¼ºµÈ µ¿Àû °´Ã¼ ÁöÇâ ±â¹ÝÀÇ °ø°³ ¼Ò½º Æ÷ÅÐ ½Ã½ºÅÛÀÌ´Ù. XOOPS¸¦ À§ÇÑ SPAW PHP WYSIWYG ÆíÁý±â ÄÁÆ®·ÑÀÇ ¸î¸î º¹»çº»µéÀº 'spaw_control.class.php' ½ºÅ©¸³Æ®ÀÇ 'spaw_root' Àμö·Î Àü´ÞµÈ »ç¿ëÀÚ°¡ Á¦°øÇÑ ÀԷ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ °ËÁõÀ¸·Î ÀÎÇÏ¿©, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¾ÇÀÇÀûÀÎ PHP ÆÄÀϵéÀ» Æ÷ÇÔ(Include)ÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. ¸¸¾à register_globals ¿É¼ÇÀÌ »ç¿ëÇÔÀ¸·Î µÇ¾î ÀÖ´Ù¸é, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â Àß Á¶ÀÛµÈ URL ¿äûÀ» º¸³» ¿µÇâÀ» ¹Þ´Â È£½ºÆ® »ó¿¡ ÀÓÀÇÀÇ PHP ÄÚµå¿Í ¿î¿µÃ¼Á¦ ¸í·ÉµéÀ» ½ÇÇàÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.xoops.org/modules/news/article.php?storyid=3799
http://secunia.com/advisories/25522
http://secunia.com/advisories/25652
http://secunia.com/advisories/25665
http://secunia.com/advisories/25667


* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Planet XOOPS, XOOPS WIWIMOD module ¹öÀü 0.4
Planet XOOPS, XOOPS TinyContent module ¹öÀü 1.5¿Í ±× ÀÌÀüÀÇ ¹öÀüµé
Planet XOOPS, XOOPS Cjay Content WYSIWYG IE module ¹öÀü 3.0°ú ±× ÀÌÀüÀÇ ¹öÀüµé
Planet XOOPS, XOOPS XT-Conteudo module ¹öÀü 1.52°ú ±× ÀÌÀüÀÇ ¹öÀüµé
Planet XOOPS, XOOPS icontent module ¹öÀü 1.0
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ 2014³â 6¿ù ÇöÀç ¾÷±×·¹À̵峪 ÆÐÄ¡´Â ³ª¿Í ÀÖÁö ¾Ê´Ù.

Â÷¼±Ã¥À¸·Î PHPÀÇ 'register_globals' ¼³Á¤À» »ç¿ë ÁßÁö½ÃÄÑ ³õ´Â´Ù.

-- ȤÀº --

´ÙÀ½ À¥ »çÀÌÆ®µé¿¡¼­ »õ·Ó°Ô ¼öÁ¤µÈ ¹öÀüÀÌ ´Ù¿î·Îµå °¡´ÉÇÒ ¶§ Xoops ModuleÀÇ ±³Á¤µÈ ¾î¶² ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

XOOPS TinyContent ¸ðµâÀÇ °æ¿ì:
http://www.chapi.de/category/xoops/

XOOPS Cjay Content WYSIWYG IE ¸ðµâÀÇ °æ¿ì:
http://www.xoops.org/modules/repository/singlefile.php?cid=94&lid=1123

XOOPS XT-Conteudo ¸ðµâÀÇ °æ¿ì:
http://www.xoops.org/modules/repository/singlefile.php?cid=94&lid=1405

XOOPS icontent ¸ðµâÀÇ °æ¿ì:
http://www.xoops.org/modules/news/article.php?storyid=1207
°ü·Ã URL CVE-2007-3057,CVE-2007-3220,CVE-2007-3221,CVE-2007-3237,CVE-2007-3289 (CVE)
°ü·Ã URL 24302,24470 (SecurityFocus)
°ü·Ã URL 34681,34855,34856,34839,34951 (ISS)