English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 210114
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç Mambo Open Source´Â MOStlyCE ±¸¼º¿ä¼ÒÀÇ 'connector.php' ½ºÅ©¸³Æ®¿¡ ÀÖ´Â ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÑ °ÍÀ¸·Î ³ªÅ¸³­´Ù. Mambo Open Source(¿¹Àü¿¡´Â Mambo Site Server·Î ºÒ¸²)´Â ÀÎÅÍ³Ý Æ÷ÅÐ ¹× ÄÜÅÙÃ÷ °ü¸® ¼ÒÇÁÆ®¿þ¾îÀÌ´Ù. MOStlyContent Editor (MOStlyCE)´Â Mambo¸¦ À§ÇÑ µðÆúÆ® WYSIWYG ÆíÁý±âÀÌ´Ù. Mambo 4.6.3¿¡ Æ÷ÇÔµÈ MOStlyCE 2.4´Â ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ ¹®Á¦µéÀº »ç¿ëÀÚ°¡ Á¦°øÇÑ µ¥ÀÌÅ͸¦ ó¸®ÇÒ ¶§ "mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php" ½ºÅ©¸³Æ®¿¡ ÀÖ´Â ÀÔ·Â °ËÁõ ¿À·ùµé¿¡¼­ ±âÀÎÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº °ø°ÝÀڵ鿡 ÀÇÇØ ÀÓÀÇÀÇ ÆÄÀÏÀ» »èÁ¦Çϰųª, ¹Î°¨ÇÑ Á¤º¸¸¦ ¾Ë¾Æ³»°Å³ª, MamboÀÇ ¼³Á¤ ÆÄÀÏÀÇ À̸§À» º¯°æÇϰųª, ȤÀº ¿µÇâÀ» ¹Þ´Â À¥ »çÀÌÆ®ÀÇ È¯°æÇÏ¿¡¼­ ÀÓÀÇÀÇ ½ºÅ©¸³Æà Äڵ尡 »ç¿ëÀÚ ºê¶ó¿ìÀú¿¡ ÀÇÇØ ½ÇÇàµÉ ¼ö ÀÖ°Ô Çϴµ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2008-01/0386.html
http://secunia.com/advisories/28670

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Mamboserver, Mambo Open Source ¹öÀü 4.6.3°ú ±× ÀÌÀüÀÇ ¹öÀüµé
Mambo MOStlyCE ¹öÀü 2.4¸¦ Æ÷ÇÔÇÑ ¿©·¯ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ ´ÙÀ½ Mambo º¸¾È °øÁö¸¦ ÂüÁ¶ÇÏ¿© MOStlyCEÀÇ °¡Àå ÃֽŠ¹öÀü(3.0 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://sourceforge.net/projects/mostlyce/

Â÷¼±Ã¥À¸·Î "mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php" ½ºÅ©¸³Æ®·ÎÀÇ ¾×¼¼½º¸¦ Á¦ÇÑÇÑ´Ù. (¿¹¸¦ µé¾î, ".htaccess" ¸¦ »ç¿ëÇÏ¿©)
°ü·Ã URL CVE-2008-7215 (CVE)
°ü·Ã URL 27472 (SecurityFocus)
°ü·Ã URL 39986 (ISS)