Ãë¾àÁ¡ID |
210086 |
À§Çèµµ |
20 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç WordPress ÇÁ·Î±×·¥Àº 'wp-includes/query.php' ½ºÅ©¸³Æ®¿¡ ÀÖ´Â Á¤º¸ ³ëÃâ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. WordPress ´Â MySQL µ¥ÀÌÅͺ£À̽º¸¦ »ç¿ëÇÏ´Â PHP ±â¹ÝÀÇ ÃâÆÇ(publication) ÇÁ·Î±×·¥À¸·Î¼, ¹«·á·Î »ç¿ë °¡´ÉÇÑ ÇÁ·Î±×·¥ÀÌ´Ù. WordPress ¹öÀü 2.3.1°ú ±× ÀÌÀüÀÇ ¹öÀüµéÀº 'wp-includes/query.php' ½ºÅ©¸³Æ®¿¡ ÀÖ´Â 'is_admin()' ÇÔ¼ö¿¡ ÀÖ´Â °ü¸®ÀÚ ½Å¿ëÁ¤º¸¿¡ ´ëÇÑ ºÎÀûÀýÇÑ °Ë»ç·Î ÀÎÇÏ¿©, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¹Î°¨ÇÑ Á¤º¸¸¦ º¼ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. ¹®ÀÚ¿ 'wp-admin/'¸¦ Æ÷ÇÔÇÏ´Â 'index.php' ½ºÅ©¸³Æ®·ÎÀÇ Àß Á¶ÀÛµÈ URL ¿äûÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© ¾î¶² º¸¾È Á¦ÇѵéÀ» ¿ìȸÇÏ°í ¹Î°¨ÇÑ È¤Àº ½Ã½ºÅÛ Á¤º¸¸¦ ȹµæÇÒ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://trac.wordpress.org/ticket/5487 http://www.securityfocus.com/archive/1/485160/30/0/threaded http://secunia.com/advisories/28130/
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Matthew Mullenweg, WordPress ¹öÀü 2.3.1°ú ±× ÀÌÀüÀÇ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
WordPress ´Ù¿î·Îµå À¥ »çÀÌÆ®ÀÎ http://wordpress.org/download/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â WordPressÀÇ °¡Àå ÃֽŠ¹öÀü(2.3.2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
26885 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|