English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21742
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç phpMyAdmin ÇÁ·Î±×·¥Àº 'grab_globals.lib.php' ½ºÅ©¸³Æ®¿¡ ÀÖ´Â ·ÎÄà ÆÄÀÏ Æ÷ÇÔ(Include) Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. phpMyAdmin´Â À¥À» ÅëÇØ MySQL¸¦ °ü¸®ÇÏ·Á´Â ¸ñÀûÀÇ PHP·Î Á¦ÀÛµÈ ÅøÀÌ´Ù. ÇöÀç ÀÌ ÅøÀº µ¥ÀÌÅͺ£À̽ºÀÇ »ý¼º°ú »èÁ¦, Å×À̺íÀÇ »ý¼º/»èÁ¦/º¯°æ, ÇʵåÀÇ »èÁ¦/ÆíÁý/Ãß°¡, ÀÓÀÇÀÇ SQL ¹®ÀÇ ½ÇÇà, Çʵå»óÀÇ Å° °ü¸® ±â´É µîÀ» Á¦°øÇÑ´Ù. phpMyAdmin ¹öÀü 2.6.4-pl1°ú ±× ÀÌÀüÀÇ ¹öÀüµéÀº './libraries/grab_globals.lib.php' ½ºÅ©¸³Æ®ÀÇ 'usesubform' Àμö·Î °Ç³×Áø »ç¿ëÀÚ°¡ Á¦°øÇÑ ÀԷ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ ÇÊÅ͸µÀ¸·Î ÀÎÇÏ¿© ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ À¥ rootÀÇ ¿ÜºÎ¿¡ ÀÖ´Â ÆÄÀÏÀ» º¼ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. "dot dot" ½ÃÄö½ºµé(/../)À» Æ÷ÇÔÇÏ´Â Àß Á¶ÀÛµÈ URLÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â À¥ ¼­ºñ½ºÀÇ ±ÇÇÑÀ» °¡Áö°í À¥ root µð·ºÅ丮ÀÇ ¿ÜºÎ¿¡ ÀÖ´Â ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐ¾î ³¾ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://securityreason.com/achievement_securityalert/24
http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0225.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Tobias Ratschiller, phpMyAdmin 2.6.4-pl1°ú ±× ÀÌÀüÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ phpMyAdminÀÇ ´Ù¿î·Îµå À¥ ÆäÀÌÁöÀÎ http://www.phpmyadmin.net/home_page/downloads.php ¿¡¼­ ÃֽŹöÀüÀÇ phpMyAdminÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2005-3299 (CVE)
°ü·Ã URL 15053 (SecurityFocus)
°ü·Ã URL 22558 (ISS)