English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21768
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®¿¡´Â ¹öÀü 1.2 ȤÀº ±× ÀÌÀüÀÇ RunCMSÀÇ ¾î¶² ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖ´Â °ÍÀ¸·Î Å×½ºÆ®µÈ´Ù. RunCMS / E-XoopsÀº XOOPS¿¡¼­ °³¹ßµÈ, PHP·Î Á¦ÀÛµÈ ¹«·á·Î »ç¿ë °¡´ÉÇÑ Ä¿¹Â´ÏƼ °ü¸® ½Ã½ºÅÛ(Community Management System)ÀÌ´Ù. RUNCMS ¹öÀü 1.2¿Í ±× ÀÌÀüÀÇ ¹öÀüµéÀº ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº °ø°ÝÀÚµéÀÌ POST ¸Þ½îµå(method)¸¦ ÅëÇØ Àü´ÞÇÏ´Â ¹æ¹ýÀ¸·Î ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ ÀÓÀÇÀÇ º¯¼öµéÀ» µ¤¾î¾µ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖÀ¸¸ç SQL ÁÖÀÔ °ø°ÝµéÀ» ¼öÇàÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.gulftech.org/?node=research&article_id=00094-08192005
http://secunia.com/advisories/16514/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
RUNCMS ¹öÀü 1.2¿Í ±× ÀÌÀüÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ º¸°í¿¡ µû¸£¸é Ãë¾àÁ¡µéÀº 2005³â 7¿ù Áß¼ø °æ¿¡ º°µµÀÇ ¾Ë¸²¾øÀÌ ÆÐÄ¡µÇ¾ú´Ù°í ÇÑ´Ù.

RunCMS À¥ »çÀÌÆ®ÀÎ http://sourceforge.net/projects/runcms/¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â RunCMSÀÇ °¡Àå ÃֽŠ¹öÀü(1.2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2005-2691,CVE-2005-2692 (CVE)
°ü·Ã URL 14631,14634 (SecurityFocus)
°ü·Ã URL 21945,21949 (ISS)