English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21725
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç phpPgAds/phpAdsNew ÇÁ·Î±×·¥Àº ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÑ °ÍÀ¸·Î ³ªÅ¸³­´Ù. phpPgAds¿Í phpAdsNew´Â PHP·Î Á¦ÀÛµÈ ¹é¿£µå µ¥ÀÌÅͺ£À̽º·Î PostgreSQL¸¦ »ç¿ëÇÏ´Â ¹è³Ê °ü¸® ¹× ÃßÀû ½Ã½ºÅÛÀÌ´Ù. phpPgAds¿Í phpAdsNewÀÇ 2.0.6 ÀÌÀüÀÇ ¹öÀüµéÀº ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ¿¡ ÀÇÇØ ÀÓÀÇÀÇ PHP ÄÚµå ½ÇÇà, SQL ÁÖÀÔ ±×¸®°í ·ÎÄà ÆÄÀÏ Æ÷ÇÔ °ø°ÝµéÀ» ¼öÇàÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù:

1) 'adxmlrpc.php' ½ºÅ©¸³Æ®¿¡ ÀÖ´Â ¿ø°Ý PHP ÄÚµå ÁÖÀÔ Ãë¾àÁ¡
2) 'libraries/lib-view-direct.inc.php' ½ºÅ©¸³Æ®¿¡ ÀÖ´Â SQL ÁÖÀÔ Ãë¾àÁ¡
3) 'adlayer.php' ½ºÅ©¸³Æ®¿Í 'admin/js-form.php' ½ºÅ©¸³Æ®¿¡ ÀÖ´Â ´ÙÁßÀÇ ·ÎÄà ÆÄÀÏ Æ÷ÇÔ Ãë¾àÁ¡µé

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/408423/30/120/threaded
http://secunia.com/advisories/16468/
http://secunia.com/advisories/16469/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
SourceForge.net, phpPgAds 2.0.6 ÀÌÀüÀÇ ¹öÀüµé
SourceForge.net, phpAdsNew 2.0.6 ÀÌÀüÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ ´ÙÀ½ SourceForge.net À¥ »çÀÌÆ®µé¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â phpPgAds ȤÀº phpAdsNewÀÇ °¡Àå ÃֽŠ¹öÀü(2.0.6 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:

phpPgAdsÀÇ °æ¿ì:
http://prdownloads.sourceforge.net/phppgads

phpAdsNewÀÇ °æ¿ì:
http://prdownloads.sourceforge.net/phpadsnew
°ü·Ã URL CVE-2005-2498,CVE-2005-2635,CVE-2005-2636 (CVE)
°ü·Ã URL 14560,14583,14588,14584,14591 (SecurityFocus)
°ü·Ã URL 21842,21875,21877,21879,21880 (ISS)