English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21728
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®¿¡´Â ¹öÀü 4.66z ȤÀº ±× ÀÌÀüÀÇ PBLang BBSÀÇ ¾î¶² ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖ´Â °ÍÀ¸·Î Å×½ºÆ® µÇ¾îÁø´Ù. PBLangÀº PHP·Î Á¦ÀÛµÈ ¹«·á·Î »ç¿ë °¡´ÉÇÑ BBS(bulletin board system)ÀÌ´Ù. PBLang 4.66z ÀÌÇÏÀÇ ¹öÀüµéÀº ´ÙÀ½°ú °°Àº ¿ø°Ý ÄÚµå ½ÇÇà, µð·ºÅ丮 Ž»ö, Á¤º¸ ³ëÃâ, Cross-Site Scripting, ±×¸®°í °æ·Î¸í ³ëÃâÀ» Æ÷ÇÔÇÑ ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù:

1) ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾àÁ¡: ¿ø°ÝÁöÀÇ »ç¿ëÀÚ°¡ »õ·Î¿î »ç¿ëÀÚ¸íÀ» µî·ÏÇÒ ¶§, »ç¿ëÀÚ°¡ Á¦°øÇÕ ÀÔ·ÂÀ» Æ÷ÇÔÇÑ ÆÄÀÏÀÌ '/db/members' µð·ºÅ丮¿¡ »ý¼ºµÈ´Ù. ¿ø°ÝÁöÀÇ »ç¿ëÀÚ´Â Àß Á¶ÀÛµÈ 'location' °ªÀ» Á¦°øÇÏ¿© ÀÓÀÇÀÇ PHP Äڵ尡 ±× ÆÄÀÏ¿¡ »ðÀԵǵµ·Ï ÇÒ ¼ö ÀÖ´Ù.
2) setcookie.php ½ºÅ©¸³Æ®¿¡ ÀÖ´Â µð·ºÅ丮 Ž»ö Ãë¾àÁ¡
3) setcookie.php ½ºÅ©¸³Æ®¿¡ ÀÖ´Â Cross-Site Scripting Ãë¾àÁ¡
4) setcookie.php ½ºÅ©¸³Æ®¿¡ ÀÖ´Â ¹°¸®Àû °æ·Î¸í ³ëÃâ Ãë¾àÁ¡

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2005-09/0078.html
http://securitytracker.com/alerts/2005/Sep/1014861.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Dr. Martinus, PBLang 4.66z ÀÌÇÏÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ SourceForge.net À¥ »çÀÌÆ®ÀÎ https://sourceforge.net/project/showfiles.php?group_id=62953 ¿¡¼­ ÃֽŹöÀüÀÇ PBLangÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2005-2892,CVE-2005-2894 (CVE)
°ü·Ã URL 14765,14766 (SecurityFocus)
°ü·Ã URL 22185,22187,22189,22190,22191 (ISS)