English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21646
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç phpPgAdmin´Â formLanguage Àμö¿¡ ÀÖ´Â µð·ºÅ丮 Ž»ö Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. phpPgAdmin´Â PostgreSQL µ¥ÀÌÅͺ£À̽º ¼­¹ö¸¦ À§ÇÑ ¿ÏÀüÇÑ ±â´ÉÀ» ÇÏ´Â À¥ ±â¹ÝÀÇ °ü¸® À¯Æ¿¸®Æ¼ÀÌ´Ù. phpPgAdmin ¹öÀü 3.5.3À» Æ÷ÇÔÇÑ ¿©·¯ ¹öÀüµéÀº login.php ½ºÅ©¸³Æ®ÀÇ formLanguage Àμö¿¡ »ç¿ëÀÚ°¡ Á¦°øÇÑ ÀÔ·ÂÀ» ÀûÀýÇÏ°Ô °ËÁõÇÏÁö ¸øÇÔÀ¸·Î ÀÎÇÏ¿© µð·ºÅ丮 Ž»ö Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. ¸¸¾à register_globals°¡ »ç¿ë ÁßÀ̶ó¸é ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â login.php ½ºÅ©¸³Æ®ÀÇ formLanguage Àμö¿¡ "%2e%2e%2f" (encoded dot dot) ½ÃÄö½ºµéÀ» Æ÷ÇÔÇÏ´Â Àß Á¶ÀÛµÈ URL ¿äûÀ» º¸³» ¹®¼­ root µð·ºÅ丮 ¿ÜºÎ¿¡ ÀÖ´Â ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐ¾î °¥ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://secunia.com/advisories/15941/
http://archives.neohapsis.com/archives/dailydave/2005-q3/0010.html
http://securitytracker.com/id?1014414
http://www.vuxml.org/freebsd/88188a8c-eff6-11d9-8310-0001020eed82.html
http://sourceforge.net/project/shownotes.php?release_id=342261

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
SourceForge.net, phpPgAdmin ¹öÀü 3.5.3À» Æ÷ÇÔÇÑ ¿©·¯ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ phpPgAdmin À¥ »çÀÌÆ®ÀÎ http://sourceforge.net/projects/phppgadmin ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â phpPgAdminÀÇ °¡Àå ÃֽŠ¹öÀü(3.5.4 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2005-2256 (CVE)
°ü·Ã URL 14142 (SecurityFocus)
°ü·Ã URL 21265 (ISS)