| 
   
            
 	            | Ãë¾àÁ¡ID | 21544 |   
 	            | À§Çèµµ | 40 |  
 	            | Æ÷Æ® | 80, ... |  	
 	            | ÇÁ·ÎÅäÄÝ | TCP |  	
 	            | ºÐ·ù | CGI |  	
 	            | »ó¼¼¼³¸í | ÇØ´ç Mambo Open Source´Â Tar.php ½ºÅ©¸³Æ®¿¡ ÀÖ´Â PHP ¿ø°Ý ÄÚµå ÁÖÀÔ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Mambo Open Source(¿¹Àü¿¡´Â Mambo Site Server·Î ºÒ¸²)´Â ÀÎÅÍ³Ý Æ÷ÅÐ ¹× ÄÜÅÙÃ÷ °ü¸® ¼ÒÇÁÆ®¿þ¾îÀÌ´Ù. Mambo Open Source 4.5.2 ÀÌÇÏÀÇ ¹öÀüµéÀº 'Tar.php' ½ºÅ©¸³Æ®ÀÇ mosConfig_absolute_path Àμö·Î °Ç³×Áø »ç¿ëÀÚ Á¦°ø ÀԷ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ ÇÊÅ͸µÀ¸·Î ÀÎÇÏ¿© Á¦ 3ÀÇ ¼¹ö »ó¿¡¼ È£½ºÆÃÇÏ´Â ¾ÇÀÇÀûÀÎ PHP ÆÄÀϵéÀ» Æ÷ÇÔ(Include)ÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¸¸¾à PHP ¼³Á¤ ÆÄÀÏÀÌ register_globals ¼³Á¤À» 'on'À¸·Î ¼³Á¤Çϰí ÀÖ´Ù¸é ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â Àß Á¶ÀÛµÈ URLÀ» Á¦°øÇÏ¿© À¥ ¼ºñ½ºÀÇ ±ÇÇÑÀ» °¡Áö°í ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡¼ ÀÓÀÇÀÇ PHP Äڵ带 IncludeÇÏ¿© ½ÇÇà½Ãų ¼ö ÀÖ´Ù. 
 * Âü°í »çÀÌÆ®:
 http://www.securitytracker.com/alerts/2005/Feb/1013250.html
 http://www.osvdb.org/14021
 http://help.mamboserver.com/index.php?option=com_content&task=view&id=426&Itemid=88
 
 * ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
 Miro Construct Pty »ç, Mambo Open Source 4.5.2 ÀÌÇÏÀÇ ¹öÀüµé
 ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
 |  	
 	            | ÇØ°áÃ¥ | ´ÙÀ½ Mamboportal ´Ù¿î·Îµå À¥ ÆäÀÌÁö¿¡¼ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â Mambo Open SourceÀÇ °¡Àå ÃֽйöÀü(4.5.2.1 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. http://sourceforge.net/projects/mambo/
 |  	
 	            | °ü·Ã URL | CVE-2005-0512 (CVE) |  	
 	            | °ü·Ã URL | 12608 (SecurityFocus) |  
 	            | °ü·Ã URL | 19429 (ISS) |  |