Ãë¾àÁ¡ID |
21652 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç PHPAuction ¼ÒÇÁÆ®¿þ¾î´Â ´ÙÁßÀÇ ¿ø°Ý Ãë¾àÁ¡µé¿¡ Ãë¾àÇÑ °ÍÀ¸·Î º¸ÀδÙ. PHPAuction´Â Gianluca Baldo¿¡ ÀÇÇØ °³¹ßµÈ °ø°³ ¼Ò½º ¿Â¶óÀÎ °æ¸Å ¼ÒÇÁÆ®¿þ¾î ÆÐÅ°ÁöÀÌ´Ù. PHPAuction ¹öÀü 2.5¸¦ Æ÷ÇÔÇÑ ¿©·¯ ¹öÀüµéÀº ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ »çÀÌÆ®¿¡ ´ëÇÑ ºñÀΰ¡µÈ ¾×¼¼½º¸¦ ¾ò¾î³¾ ¼ö ÀÖÀ¸¸ç SQL ÁÖÀÔ, Cross-Site Scripting °ø°Ý ±×¸®°í ÀÓÀÇÀÇ PHP ÄÚµå ½ÇÇàÀ» ¼öÇàÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁÙ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://securitytracker.com/alerts/2005/Jul/1014423.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Gianluca Baldo, PHPAuction ¹öÀü 2.5¸¦ Æ÷ÇÔÇÑ ¿©·¯ ¹öÀüµé Linux Any version Microsoft Windows Any version |
ÇØ°áÃ¥ |
PHPAuctionÀº ´õ ÀÌ»ó Áö¿øµÇÁö ¾Ê´Â´Ù. º¸¾ÈÀ» À§ÇØ enuuk auctionÀ¸·Î ´ëüÇϰųª, ´Ù¸¥ ¼Ö·ç¼ÇÀ¸·Î ´ëüÇÒ °ÍÀ» ±Ç°íÇÑ´Ù. http://www.phpauction.net/products/enuuk-auction-platform |
°ü·Ã URL |
CVE-2005-2252,CVE-2005-2253,CVE-2005-2254,CVE-2005-2255 (CVE) |
°ü·Ã URL |
14184 (SecurityFocus) |
°ü·Ã URL |
21306,21308,21310,21311 (ISS) |
|