English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21162
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥¼­¹ö´Â PHP-Nuke (bb_smilies.php)¿¡ ÀÖ´Â º¸¾È»óÀÇ ¹®Á¦¿¡ Ãë¾àÇÏ´Ù.
±× Ãë¾àÁ¡Àº PHP-NukeÀÇ bb_smilies.php¿¡ ÀÇÇÑ ÁúÀǸ¦ ºÎÀûÀýÇÏ°Ô Ã³¸®ÇÔÀ¸·Î½á ¹ß»ýÇϸç, ±×°á°ú À¥¼­¹öÀÇ ±ÇÇÑÀ¸·Î ¼­¹ö³»ÀÇ ÀÓÀÇÀÇ ÆÄÀÏÀ» º¼ ¼ö ÀÖ´Ù. ¶ÇÇÑ ±× PHP ÇÁ·Î±×·¥¿¡ ÀÖ´Â À¯»çÇÑ Ãë¾àÁ¡Àº bb_smiliesÀÇ °ü¸®ÀÚÀÇ ÆÐ½º¿öµå¸¦ º¯°æÇÔÀ¸·Î½á À¥¼­¹öÀÇ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ ¸í·ÉÀ» ¼öÇàÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù.

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
PHP-Nuke
ÇØ°áÃ¥ bb_smilies.php °ú bbcode_ref.php¿¡ ÀÖ´Â ´ÙÀ½ ¶óÀεéÀ» ¼öÁ¤ÇØ¾ß ÇÑ´Ù.

if ($userdata[9] != ') $themes = 'themes/$userdata[9]/theme.php';
else $themes = 'themes/$Default_Theme/theme.php';

* ´ÙÀ½ ¶óÀÎÀ¸·Î ¼öÁ¤
if ($userdata[9] != ') $themes = 'themes/$userdata[9]/theme.php';
else $themes = 'themes/$Default_Theme/theme.php';
if ( !(strstr(basename($themes),'theme.php')) || !(file_exists($themes)) ){
echo 'Invalid Theme'; exit;}
include ('$themes');

ȤÀº °¡Àå ÃֽйöÀüÀÎ ¹öÀü 4.4.1 ÀÌ»óÀ¸·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2001-0320 (CVE)
°ü·Ã URL 2422 (SecurityFocus)
°ü·Ã URL 6183 (ISS)