English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21244
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥¼­¹ö¿¡ ¼³Ä¡µÈ phpMyAdmin ÆÐŰÁö´Â ´ÙÁßÀÇ Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
phpMyAdmin´Â À¥À» ÅëÇØ MySQL¸¦ °ü¸®ÇÏ·Á´Â ¸ñÀûÀÇ PHP·Î Á¦ÀÛµÈ ÅøÀÌ´Ù. ÇöÀç ÀÌ ÅøÀº µ¥ÀÌÅͺ£À̽ºÀÇ »ý¼º°ú »èÁ¦, Å×À̺íÀÇ »ý¼º/»èÁ¦/º¯°æ, ÇʵåÀÇ »èÁ¦/ÆíÁý/Ãß°¡, ÀÓÀÇÀÇ SQL ¹®ÀÇ ½ÇÇà, Çʵå»óÀÇ Å° °ü¸® ±â´É µîÀ» Á¦°øÇÑ´Ù. phpMyAdmin ÆÐŰÁö´Â ´ÙÀ½°ú °°Àº ¹®Á¦Á¡µéÀ» °¡Áö°í ÀÖ´Ù:

- ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ phpMyAdminÀÇ ¹°¸®Àû °æ·Î¸íÀ» ¾Ë¾Æ³¾ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
- ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ Cross-Site scriptingÀ» ÅëÇØ »ç¿ëÀÚµéÀÇ Äí۵éÀ» ÈÉÃÄ °¥ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
- ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ Ãë¾àÇÑ ¼­¹ö»óÀÇ ÀÓÀÇÀÇ µð·ºÅ丮µéÀÇ ³»¿ëÀ» ¸®½ºÆ®ÇØ º¼ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/325641

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
phpMyAdmin 2.5.1 ÀÌÇÏ
Windows ¸ðµç ¹öÀü
UNIX/Linux ¸ðµç ¹öÀü
ÇØ°áÃ¥ ´ÙÀ½ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ÃֽйöÀüÀÇ phpMyAdmin(2.5.2ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù.
http://www.phpmyadmin.net/home_page/index.php
°ü·Ã URL (CVE)
°ü·Ã URL 7965,7964,7963,7962 (SecurityFocus)
°ü·Ã URL (ISS)