English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21406
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç phpBugTracker Æ÷·Î±×·¥¿¡´Â bug.php ½ºÅ©¸³Æ®¸¦ ÅëÇÑ SQL Injection Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
phpBugTracker´Â Microsoft Windows, Linux, Unix °è¿­ÀÇ ¿î¿µÃ¼Á¦¸¦ À§ÇÑ À¥ ±â¹ÝÀÇ Ãë¾àÁ¡ ÃßÀû(tracking) ½Ã½ºÅÛÀÌ´Ù. phpBugTracker 0.9.1 ¹öÀüÀÇ °æ¿ì, SQL Injection °ø°Ý¿¡ ¿µÇâÀ» ¹ÞÀ» ¼ö ÀÖ´Ù. ÀÌ´Â ¾ÖÇø®ÄÉÀ̼ÇÀÌ 'bug.php' ½ºÅ©¸³Æ®¿¡¼­ »ç¿ëÀÚ ÀÔ·ÂÀ» ÀûÀýÈ÷ ÇÊÅ͸µÇÏÁö ¸øÇϱ⠶§¹®ÀÌ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº 'bug_id' º¯¼ö¿¡ SQL Äõ¸®¸¦ Æ÷ÇÔÇÏ´Â Àß Á¶ÀÛµÈ URL À» ´ë»ó ½Ã½ºÅÛ¿¡ Àü´ÞÇÏ´Â ¹æ¹ýÀ¸·Î, ½Ã½ºÅÛÀÇ Áß¿äÇÑ Á¤º¸¸¦ ȹµæÇϰųª ÈÄÀ§ µ¥ÀÌÅͺ£À̽º »óÀÇ µ¥ÀÌÅ͸¦ Ãß°¡, »èÁ¦, º¯Á¶ÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.osvdb.org/5384
http://securitytracker.com/alerts/2004/Apr/1009821.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Benjamin Curtis, phpBugTracker 0.9.1
¸ðµç ¿î¿µÃ¼Á¦ÀÇ ¸ðµç ¹öÀüµé
ÇØ°áÃ¥ ´ÙÀ½ phpBugTracker À¥ »çÀÌÆ®¿¡¼­ phpBugTrackerÀÇ »õ ¹öÀüÀ» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
http://phpbt.sourceforge.net/
°ü·Ã URL CVE-2004-1519 (CVE)
°ü·Ã URL 10153 (SecurityFocus)
°ü·Ã URL 18053 (ISS)