Ãë¾àÁ¡ID |
210173 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛ¿¡´Â WordPressÀÇ 5.1.1. ÀÌÀü ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖÀ¸¸ç, ¿©·¯ °¡Áö Ãë¾àÁ¡ÀÇ ¿µÇâÀ»¹Þ½À´Ï´Ù. - ºÎÀûÀýÇÑ À¯È¿¼º È®ÀÎÀ¸·Î ÀÎÇØ ÁÖ¼® ¾ç½Ä¿¡ XSRF (Cross-Site Request Forgery) Ãë¾àÁ¡ÀÌ Á¸ÀçÇÕ´Ï´Ù. ¿ø°Ý °ø°ÝÀÚ´Â »ç¿ëÀÚ°¡ ¼ÓÀÓ¼ö·Î À¥ ÆäÀÌÁö¸¦ ¹æ¹®Çϵµ·Ï À¯µµÇÏ¿© ħÀÔÀÚ°¡ °ü¸®ÀÚ¸¦ ´ë½ÅÇÏ¿© ÀÇ°ßÀ» ÀÛ¼ºÇÒ ¼öÀÖ°ÔÇÔÀ¸·Î½áÀÌ Ãë¾àÁ¡À» ¾Ç¿ë ÇÒ ¼ö ÀÖ½À´Ï´Ù. - »ç¿ëÀÚ Á¦°ø ÀÔ·ÂÀÇ À¯È¿¼ºÀ» ºÎÀûÀýÇÏ°Ô °Ë»çÇÏ¿© »ç¿ëÀÚ¿¡°Ô ¹ÝȯÇϱâ Àü¿¡ XSS (Cross-Site Scripting) Ãë¾àÁ¡ÀÌ Á¸ÀçÇÕ´Ï´Ù. ÀÎÁõµÇÁö ¾ÊÀº ¿ø°Ý °ø°ÝÀÚ´Â »ç¿ëÀÚ°¡ Ư¼öÇÏ°Ô Á¶ÀÛ µÈ URLÀ» Ŭ¸¯Çϵµ·Ï À¯µµÇÏ¿© »ç¿ëÀÚÀÇ ºê¶ó¿ìÀú ¼¼¼Ç¿¡¼ ÀÓÀÇÀÇ ½ºÅ©¸³Æ® Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ½À´Ï´Ù. * Âü°í »çÀÌÆ®: https://wordpress.org/support/wordpress-version/version-5-1-1/
* ¿µÇâ¹Þ´Â Ç÷§Æû: WordPress prior to 5.1.1 Any operating system Any version |
ÇØ°áÃ¥ |
´ÙÀ½ WordPress ´Ù¿î·Îµå À¥ ÆäÀÌÁö http://wordpress.org/download/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â ÀÌ Ãë¾àÁ¡À» ÇØ°áÇÑ WordPress ¹öÀü(5.1.1 ¶Ç´Â ±× ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|