| Ãë¾àÁ¡ID |
21236 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
CGI |
| »ó¼¼¼³¸í |
ÇØ´ç ZeroboardÀÇ login.php´Â ¿ø°ÝÁöÀÇ °ø°ÝÀڵ鿡°Ô ÀÓÀÇÀÇ ¸í·ÉÀ» ½ÇÇàÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. Zeroboard´Â Linux¿Í Unix Ç÷§Æû¿¡¼ »ç¿ëÇÒ ¼ö ÀÖ´Â PHP À¥ °Ô½ÃÆÇ ÆÐŰÁöÀÌ´Ù. Zeroboard´Â Çѱ¹¿¡¼ °¡Àå ÀαâÀÖ´Â PHP À¥ °Ô½ÃÆÇ ÁßÀÇ ÇϳªÀÌ´Ù. ƯÁ¤ ȯ°æ ÇÏ¿¡¼, Zeroboard´Â ÀÓÀÇÀÇ PHP ÆÄÀϵéÀ» Æ÷ÇÔ(include) ÇÒ ¼ö ÀÖ´Ù. Login.php ÆÄÀÏÀº ÀԷ¿¡ ´ëÇÑ Ã¼Å©¿¡ ¹®Á¦¸¦ °¡Áö°í ÀÖ´Ù. Login.php ½ºÅ©¸³Æ®¿¡ ÀÖ´Â 'id' º¯¼ö°¡ »ç¿ëÀÚ Àμö·Î Àü´ÞµÇÁö ¾ÊÀ» ¶§, $file º¯¼ö´Â °ø°ÝÀÚ ¸¶À½´ë·Î ¼³Á¤µÉ ¼ö ÀÖ´Ù. À̰ÍÀº °ø°ÝÀÚ°¡ login.php ½ºÅ©¸³Æ®¸¦ ÅëÇØ ¿ÜºÎ URL·ÎºÎÅÍ ÀÓÀÇÀÇ PHP include ÆÄÀÏÀ» ·Îµå(load)ÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Zeroboard 4.1 ~ 4.1 pl2 UNIX/Linux ¸ðµç ¹öÀü |
| ÇØ°áÃ¥ |
´ÙÀ½°ú °°ÀÌ login.php ½ºÅ©¸³Æ®¸¦ ¼öÁ¤ÇÏ¿©¾ß ÇÑ´Ù:
¶óÀÎ 15: include $file;
À»
if($id) include $file; |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|