Ãë¾àÁ¡ID |
21615 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
Invision Power BoardÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼ÒÇÁÆ®¿þ¾î¿¡´Â ±ÇÇÑ »ó½Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Invision Power Board ´Â Invision Power Services »ç¿¡¼ ¹èÆ÷ÇÏ´Â PHP ±â¹ÝÀÇ À¥ Æ÷·³(forum) ¼ÒÇÁÆ®¿þ¾î ÆÐÅ°ÁöÀÌ´Ù. Invision Power Board 1.0¿¡¼ 2.0.4±îÁöÀÇ ¹öÀüµéÀº »ç¿ëÀÚ ±×·ìµéÀ» »èÁ¦ÇÒ ¶§¿¡ ÀÖ´Â ¿À·ù·Î ÀÎÇÏ¿© ¿ø°ÝÁöÀÇ ÀÎÁõ¹ÞÀº °ø°ÝÀÚ°¡ »ó½ÂµÈ ±ÇÇÑÀ» ¾ò¾î³¾ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. root °ü¸®ÀÚ ±ÇÇÑÀ» °®Áö ¾ÊÀº ¿ø°ÝÁöÀÇ ÀÎÁõ¹ÞÀº °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© ÃæºÐÇÑ ÀÎÁõ ½Å¿ëÁ¤º¸¸¦ °¡ÁöÁö ¾ÊÀº ä root °ü¸®ÀÚ ±×·ìÀÇ ÀÏ¿øÀÌ µÉ ¼ö ÀÖ´Ù. Root °ü¸®ÀÚ ±ÇÇÑÀº ¾îÇø®ÄÉÀ̼ǰú ºÎ¼Ó µ¥ÀÌÅͺ£À̽º¿¡ ´ëÇÑ ¿ÏÀüÇÑ ¾×¼¼½º¸¦ °®´Â´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç À¥ ¼¹ö »ó¿¡ ¼³Ä¡µÈ Invision Power BoardÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://lists.grok.org.uk/pipermail/full-disclosure/2005-May/034355.html http://secunia.com/advisories/15545/
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Invision Power Services, Invision Power Board 1.0¿¡¼ 2.0.4±îÁöÀÇ ¹öÀüµé Microsoft Windows Any version |
ÇØ°áÃ¥ |
Invision Power Services ¾÷µ¥ÀÌÆ® »çÀÌÆ®ÀÎ http://www.invisionpower.com/apps/board/ ¿¡¼ ÃֽŹöÀüÀÇ IPB(2.1.0 ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2005-1816 (CVE) |
°ü·Ã URL |
13797 (SecurityFocus) |
°ü·Ã URL |
20840 (ISS) |
|