English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21652
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç PHPAuction ¼ÒÇÁÆ®¿þ¾î´Â ´ÙÁßÀÇ ¿ø°Ý Ãë¾àÁ¡µé¿¡ Ãë¾àÇÑ °ÍÀ¸·Î º¸ÀδÙ. PHPAuction´Â Gianluca Baldo¿¡ ÀÇÇØ °³¹ßµÈ °ø°³ ¼Ò½º ¿Â¶óÀÎ °æ¸Å ¼ÒÇÁÆ®¿þ¾î ÆÐÅ°ÁöÀÌ´Ù. PHPAuction ¹öÀü 2.5¸¦ Æ÷ÇÔÇÑ ¿©·¯ ¹öÀüµéÀº ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ »çÀÌÆ®¿¡ ´ëÇÑ ºñÀΰ¡µÈ ¾×¼¼½º¸¦ ¾ò¾î³¾ ¼ö ÀÖÀ¸¸ç SQL ÁÖÀÔ, Cross-Site Scripting °ø°Ý ±×¸®°í ÀÓÀÇÀÇ PHP ÄÚµå ½ÇÇàÀ» ¼öÇàÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁÙ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://securitytracker.com/alerts/2005/Jul/1014423.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Gianluca Baldo, PHPAuction ¹öÀü 2.5¸¦ Æ÷ÇÔÇÑ ¿©·¯ ¹öÀüµé
Linux Any version
Microsoft Windows Any version
ÇØ°áÃ¥ PHPAuctionÀº ´õ ÀÌ»ó Áö¿øµÇÁö ¾Ê´Â´Ù. º¸¾ÈÀ» À§ÇØ enuuk auctionÀ¸·Î ´ëüÇϰųª, ´Ù¸¥ ¼Ö·ç¼ÇÀ¸·Î ´ëüÇÒ °ÍÀ» ±Ç°íÇÑ´Ù.
http://www.phpauction.net/products/enuuk-auction-platform
°ü·Ã URL CVE-2005-2252,CVE-2005-2253,CVE-2005-2254,CVE-2005-2255 (CVE)
°ü·Ã URL 14184 (SecurityFocus)
°ü·Ã URL 21306,21308,21310,21311 (ISS)