English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21245
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥¼­¹ö¿¡ ¼³Ä¡µÈ phpBB´Â SQL injection Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
phpBB´Â °Ô½ÃÆÇ(bulletin board)À» À§ÇÑ ¿ÀÇ ¼Ò½º ¼ÒÇÁÆ®¿þ¾î ÆÐŰÁö·Î½á µ¥ÀÌÅͺ£À̽º·Î´Â MySQL, MS-SQL, PostgreSQL, Access/ODBC µîÀ» »ç¿ëÇÑ´Ù. ÀÌ SQL injection Ãë¾àÁ¡Àº phpBB¿¡¼­ "viewtopic.php" ½ºÅ©¸³Æ®¿¡ Àü´ÞµÇ´Â »ç¿ëÀÚ Á¦°ø ÀԷ°ªÀ» ºÎÀûÀýÇÏ°Ô Ã³¸®ÇÔÀ¸·Î ÀÎÇÏ¿© ¹ß»ýÇÑ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº SQL Äõ¸®°¡ Æ÷ÇÔµÈ topic_id º¯¼ö¸¦ "viewtopic.php" ½ºÅ©¸³Æ®¿¡ Àü´ÞÇÔÀ¸·Î½á, phpBB°¡ »ç¿ëÇÏ´Â µ¥ÀÌÅͺ£À̽º¸¦ ÀÓÀÇ·Î Á¶ÀÛÇÒ ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿©, »ç¿ëÀÚ MD5 ÆÐ½º¿öµå ÇØ½¬ °ªÀ» ȹµæ, Äõ¸® ·ÎÁ÷À» º¯°æ ¶Ç´Â µ¥ÀÌÅͺ£À̽º¸¦ ¼Õ»ó½ÃŰ´Â °ø°ÝÀÌ °¡´ÉÇÏ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2003-06/0151.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
phpBB 2.0.4
phpBB 2.0.5
Linux ¸ðµç ¹öÀü
Unix ¸ðµç ¹öÀü
Windows ¸ðµç ¹öÀü
ÇØ°áÃ¥ ´ÙÀ½ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© phpBB 2.0.6 ÀÌ»ó ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù.
http://www.phpbb.com/
°ü·Ã URL CVE-2003-0486 (CVE)
°ü·Ã URL 7979 (SecurityFocus)
°ü·Ã URL 12366 (ISS)