|  Ãë¾àÁ¡ID  | 
	             21346  | 
             
             
 	            |  À§Çèµµ  | 
	             40  |  
             
            
 	            |  Æ÷Æ®  | 
	             80, ...  | 
             		
            	
 	            |  ÇÁ·ÎÅäÄÝ  | 
	             TCP  | 
             	
            	
 	            |  ºÐ·ù  | 
	             CGI  | 
             			
            	
 	            |  »ó¼¼¼³¸í  | 
	             ÇØ´ç À¥ ¼¹ö¿¡ ¼³Ä¡µÇ¾î ÀÖ´Â phpMyFAQ ÇÁ·Î±×·¥ ¹öÀü¿¡ µû¸£¸é, phpMyFAQ ÇÁ·Î±×·¥¿¡´Â ÆÄÀÏ Æ÷ÇÔ(Inclusion) Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. phpMyFAQ´Â Microsoft Windows ¿î¿µÃ¼Á¦ »ó¿¡¼ ¿î¿µµÇ´Â ¹«·á·Î »ç¿ë °¡´ÉÇÑ FAQ ÇÁ·Î±×·¥À¸·Î¼, MySQL µ¥ÀÌÅͺ£À̽º¸¦ »ç¿ëÇÑ´Ù. phpMyFAQ ¹öÀü 1.3.12¿Í 1.4.0-alpha1¿¡´Â ÆÄÀÏ Æ÷ÇÔ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÏ´Â µ¥, ÀÌ´Â 'action' ÆÄ¶ó¹ÌÅ͸¦ ÅëÇØ ÀԷµǴ »ç¿ë µ¥ÀÌÅͰ¡ ÀûÀýÈ÷ ÇÊÅ͸µ µÇÁö ¸øÇÏ´Â µ¥ ±× ¿øÀÎÀÌ ÀÖ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº '\0' ¹®ÀÚ¿ ¸¶Ä§Ç¥½Ã¿Í »ó´ë°æ·Î¸¦ Á¶ÇÕÇÏ¿©, ½Ã½ºÅÛ »óÀÇ ÀÓÀÇÀÇ ÆÄÀÏÀ» º¼ ¼ö ÀÖÀ¸¸ç, °æ¿ì¿¡ µû¶ó Àß ¾Ë·ÁÁø ÆÄÀÏ¿¡ PHP Äڵ带 »ðÀÔÇÒ ¼ö ÀÖ´Ù¸é ÀÓÀÇÀÇ PHP ÄÚµå ½ÇÇ൵ °¡´ÉÇÏ´Ù.  
  * ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç phpMyFAQ ÇÁ·Î±×·¥ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù. 
  * Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0906.html http://www.osvdb.org/show/osvdb/6300
  * ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Thorsten Rinne, phpMyFAQ 1.3.12 ÀÌÇÏ Thorsten Rinne, phpMyFAQ 1.4.0-alpha1 ÀÌÇÏ Microsoft Windows Any version  | 
             
            	
 	            |  ÇØ°áÃ¥  | 
	             phpMyFAQ ´Ù¿î·Îµå »çÀÌÆ®ÀÎ http://www.phpmyfaq.de/download.php ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â phpMyFAQÀÇ °¡Àå ÃֽйöÀü(1.3.13 ¶Ç´Â 1.4.0 alpha2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.  |   
             		
            	
 	            |  °ü·Ã URL  | 
	             CVE-2004-2255 (CVE) | 
             		
            	
 	            |   °ü·Ã URL  | 
	            10374 (SecurityFocus) |  
             
            
 	            |   °ü·Ã URL  | 
	            16177 (ISS) | 
             
    	
         
         |