| Ãë¾àÁ¡ID |
21162 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
CGI |
| »ó¼¼¼³¸í |
ÇØ´ç À¥¼¹ö´Â PHP-Nuke (bb_smilies.php)¿¡ ÀÖ´Â º¸¾È»óÀÇ ¹®Á¦¿¡ Ãë¾àÇÏ´Ù. ±× Ãë¾àÁ¡Àº PHP-NukeÀÇ bb_smilies.php¿¡ ÀÇÇÑ ÁúÀǸ¦ ºÎÀûÀýÇÏ°Ô Ã³¸®ÇÔÀ¸·Î½á ¹ß»ýÇϸç, ±×°á°ú À¥¼¹öÀÇ ±ÇÇÑÀ¸·Î ¼¹ö³»ÀÇ ÀÓÀÇÀÇ ÆÄÀÏÀ» º¼ ¼ö ÀÖ´Ù. ¶ÇÇÑ ±× PHP ÇÁ·Î±×·¥¿¡ ÀÖ´Â À¯»çÇÑ Ãë¾àÁ¡Àº bb_smiliesÀÇ °ü¸®ÀÚÀÇ ÆÐ½º¿öµå¸¦ º¯°æÇÔÀ¸·Î½á À¥¼¹öÀÇ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ ¸í·ÉÀ» ¼öÇàÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: PHP-Nuke |
| ÇØ°áÃ¥ |
bb_smilies.php °ú bbcode_ref.php¿¡ ÀÖ´Â ´ÙÀ½ ¶óÀεéÀ» ¼öÁ¤ÇØ¾ß ÇÑ´Ù.
if ($userdata[9] != ') $themes = 'themes/$userdata[9]/theme.php'; else $themes = 'themes/$Default_Theme/theme.php';
* ´ÙÀ½ ¶óÀÎÀ¸·Î ¼öÁ¤ if ($userdata[9] != ') $themes = 'themes/$userdata[9]/theme.php'; else $themes = 'themes/$Default_Theme/theme.php'; if ( !(strstr(basename($themes),'theme.php')) || !(file_exists($themes)) ){ echo 'Invalid Theme'; exit;} include ('$themes');
ȤÀº °¡Àå ÃֽйöÀüÀÎ ¹öÀü 4.4.1 ÀÌ»óÀ¸·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù. |
| °ü·Ã URL |
CVE-2001-0320 (CVE) |
| °ü·Ã URL |
2422 (SecurityFocus) |
| °ü·Ã URL |
6183 (ISS) |
|