English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21762
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç CuteNews´Â show_archives.php¿Í show_news.php ½ºÅ©¸³Æ®µé¿¡ ÀÖ´Â µð·ºÅ丮 Ž»ö Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. CutePHP CuteNews´Â µ¥ÀÌÅͺ£À̽º·ÎÀÇ ÀúÀå ÇüÅ·Π°³º° ÆÄÀϵéÀ» »ç¿ëÇÏ´Â PHP ±â¹ÝÀÇ ´º½º °ü¸® ¼ÒÇÁÆ®¿þ¾î·Î¼­ ¹«·á·Î »ç¿ë °¡´ÉÇÏ´Ù. CutePHP CuteNews ¹öÀü 1.4.1°ú ±× ÀÌÀüÀÇ ¹öÀüµéÀº show_archives.php¿Í show_news.php ½ºÅ©¸³Æ®µé¿¡ ÀÖ´Â µð·ºÅ丮 Ž»ö Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. "dot dot" ½ÃÄö½ºµé(/../)À» Æ÷ÇÔÇÏ´Â Àß Á¶ÀÛµÈ URLÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ ÀÎÁõ¹ÞÁö ¾ÊÀº °ø°ÝÀÚ´Â À¥ ¼­ºñ½ºÀÇ ±ÇÇÑÀ» °¡Áö°í À¥ root µð·ºÅ丮 ¿ÜºÎÀÇ ÀÓÀÇÀÇ ÆÄÀϵéÀ» º¼ ¼ö ÀÖ´Ù. °ø°ÝÀÚ´Â ¶ÇÇÑ ÀÓÀÇÀÇ ½ºÅ©¸³Æ®µéÀ» ¾÷·ÎµåÇÒ ¼ö ÀÖÀ¸¸ç, ÀÌ´Â À¥ ¼­ºñ½ºÀÇ ±ÇÇÑÀ¸·Î ¿ø°Ý ÄÚµå ½ÇÇàÀ» ÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/415632/30/0/threaded

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
CutePHP CuteNews ¹öÀü 1.4.1°ú ±× ÀÌÀüÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ CutePHP À¥ »çÀÌÆ®ÀÎ http://cutephp.com/cutenews/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â CuteNewsÀÇ °¡Àå ÃֽŠ¹öÀü(1.4.2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2005-3507 (CVE)
°ü·Ã URL 15295 (SecurityFocus)
°ü·Ã URL (ISS)