Ãë¾àÁ¡ID |
210059 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç XOOPS ÇÁ·Î±×·¥Àº 'spaw_root' Àμö¸¦ ÅëÇÑ ¿ø°Ý ÆÄÀÏ Æ÷ÇÔ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. XOOPS´Â PHP·Î ÀÛ¼ºµÈ µ¿Àû °´Ã¼ ÁöÇâ ±â¹ÝÀÇ °ø°³ ¼Ò½º Æ÷ÅÐ ½Ã½ºÅÛÀÌ´Ù. XOOPS¸¦ À§ÇÑ SPAW PHP WYSIWYG ÆíÁý±â ÄÁÆ®·ÑÀÇ ¸î¸î º¹»çº»µéÀº 'spaw_control.class.php' ½ºÅ©¸³Æ®ÀÇ 'spaw_root' Àμö·Î Àü´ÞµÈ »ç¿ëÀÚ°¡ Á¦°øÇÑ ÀԷ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ °ËÁõÀ¸·Î ÀÎÇÏ¿©, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¾ÇÀÇÀûÀÎ PHP ÆÄÀϵéÀ» Æ÷ÇÔ(Include)ÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. ¸¸¾à register_globals ¿É¼ÇÀÌ »ç¿ëÇÔÀ¸·Î µÇ¾î ÀÖ´Ù¸é, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â Àß Á¶ÀÛµÈ URL ¿äûÀ» º¸³» ¿µÇâÀ» ¹Þ´Â È£½ºÆ® »ó¿¡ ÀÓÀÇÀÇ PHP ÄÚµå¿Í ¿î¿µÃ¼Á¦ ¸í·ÉµéÀ» ½ÇÇàÇÒ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.xoops.org/modules/news/article.php?storyid=3799 http://secunia.com/advisories/25522 http://secunia.com/advisories/25652 http://secunia.com/advisories/25665 http://secunia.com/advisories/25667
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Planet XOOPS, XOOPS WIWIMOD module ¹öÀü 0.4 Planet XOOPS, XOOPS TinyContent module ¹öÀü 1.5¿Í ±× ÀÌÀüÀÇ ¹öÀüµé Planet XOOPS, XOOPS Cjay Content WYSIWYG IE module ¹öÀü 3.0°ú ±× ÀÌÀüÀÇ ¹öÀüµé Planet XOOPS, XOOPS XT-Conteudo module ¹öÀü 1.52°ú ±× ÀÌÀüÀÇ ¹öÀüµé Planet XOOPS, XOOPS icontent module ¹öÀü 1.0 ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
2014³â 6¿ù ÇöÀç ¾÷±×·¹À̵峪 ÆÐÄ¡´Â ³ª¿Í ÀÖÁö ¾Ê´Ù.
Â÷¼±Ã¥À¸·Î PHPÀÇ 'register_globals' ¼³Á¤À» »ç¿ë ÁßÁö½ÃÄÑ ³õ´Â´Ù.
-- ȤÀº --
´ÙÀ½ À¥ »çÀÌÆ®µé¿¡¼ »õ·Ó°Ô ¼öÁ¤µÈ ¹öÀüÀÌ ´Ù¿î·Îµå °¡´ÉÇÒ ¶§ Xoops ModuleÀÇ ±³Á¤µÈ ¾î¶² ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
XOOPS TinyContent ¸ðµâÀÇ °æ¿ì: http://www.chapi.de/category/xoops/
XOOPS Cjay Content WYSIWYG IE ¸ðµâÀÇ °æ¿ì: http://www.xoops.org/modules/repository/singlefile.php?cid=94&lid=1123
XOOPS XT-Conteudo ¸ðµâÀÇ °æ¿ì: http://www.xoops.org/modules/repository/singlefile.php?cid=94&lid=1405
XOOPS icontent ¸ðµâÀÇ °æ¿ì: http://www.xoops.org/modules/news/article.php?storyid=1207 |
°ü·Ã URL |
CVE-2007-3057,CVE-2007-3220,CVE-2007-3221,CVE-2007-3237,CVE-2007-3289 (CVE) |
°ü·Ã URL |
24302,24470 (SecurityFocus) |
°ü·Ã URL |
34681,34855,34856,34839,34951 (ISS) |
|