Ãë¾àÁ¡ID |
210114 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç Mambo Open Source´Â MOStlyCE ±¸¼º¿ä¼ÒÀÇ 'connector.php' ½ºÅ©¸³Æ®¿¡ ÀÖ´Â ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÑ °ÍÀ¸·Î ³ªÅ¸³´Ù. Mambo Open Source(¿¹Àü¿¡´Â Mambo Site Server·Î ºÒ¸²)´Â ÀÎÅÍ³Ý Æ÷ÅÐ ¹× ÄÜÅÙÃ÷ °ü¸® ¼ÒÇÁÆ®¿þ¾îÀÌ´Ù. MOStlyContent Editor (MOStlyCE)´Â Mambo¸¦ À§ÇÑ µðÆúÆ® WYSIWYG ÆíÁý±âÀÌ´Ù. Mambo 4.6.3¿¡ Æ÷ÇÔµÈ MOStlyCE 2.4´Â ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ ¹®Á¦µéÀº »ç¿ëÀÚ°¡ Á¦°øÇÑ µ¥ÀÌÅ͸¦ ó¸®ÇÒ ¶§ "mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php" ½ºÅ©¸³Æ®¿¡ ÀÖ´Â ÀÔ·Â °ËÁõ ¿À·ùµé¿¡¼ ±âÀÎÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº °ø°ÝÀڵ鿡 ÀÇÇØ ÀÓÀÇÀÇ ÆÄÀÏÀ» »èÁ¦Çϰųª, ¹Î°¨ÇÑ Á¤º¸¸¦ ¾Ë¾Æ³»°Å³ª, MamboÀÇ ¼³Á¤ ÆÄÀÏÀÇ À̸§À» º¯°æÇϰųª, ȤÀº ¿µÇâÀ» ¹Þ´Â À¥ »çÀÌÆ®ÀÇ È¯°æÇÏ¿¡¼ ÀÓÀÇÀÇ ½ºÅ©¸³Æà Äڵ尡 »ç¿ëÀÚ ºê¶ó¿ìÀú¿¡ ÀÇÇØ ½ÇÇàµÉ ¼ö ÀÖ°Ô Çϴµ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/bugtraq/2008-01/0386.html http://secunia.com/advisories/28670
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Mamboserver, Mambo Open Source ¹öÀü 4.6.3°ú ±× ÀÌÀüÀÇ ¹öÀüµé Mambo MOStlyCE ¹öÀü 2.4¸¦ Æ÷ÇÔÇÑ ¿©·¯ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
´ÙÀ½ Mambo º¸¾È °øÁö¸¦ ÂüÁ¶ÇÏ¿© MOStlyCEÀÇ °¡Àå ÃֽŠ¹öÀü(3.0 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://sourceforge.net/projects/mostlyce/
Â÷¼±Ã¥À¸·Î "mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php" ½ºÅ©¸³Æ®·ÎÀÇ ¾×¼¼½º¸¦ Á¦ÇÑÇÑ´Ù. (¿¹¸¦ µé¾î, ".htaccess" ¸¦ »ç¿ëÇÏ¿©) |
°ü·Ã URL |
CVE-2008-7215 (CVE) |
°ü·Ã URL |
27472 (SecurityFocus) |
°ü·Ã URL |
39986 (ISS) |
|