English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21776
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç Mambo Open Source´Â globals.php ½ºÅ©¸³Æ®¿¡ ÀÖ´Â ¿ø°Ý ÆÄÀÏ Include Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Mambo Open Source(¿¹Àü¿¡´Â Mambo Site Server·Î ºÒ¸²)´Â ÀÎÅÍ³Ý Æ÷ÅÐ ¹× ÄÜÅÙÃ÷ °ü¸® ¼ÒÇÁÆ®¿þ¾îÀÌ´Ù. Mambo Open Source 4.5.2.3 ÀÌÇÏÀÇ ¹öÀüµéÀº "globals.php" ½ºÅ©¸³Æ®ÀÇ "mosConfig_absolute_path" Àμö·Î Àü´ÞµÈ »ç¿ëÀÚ°¡ Á¦°øÇÑ ÀԷ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ °ËÁõÀ¸·Î ÀÎÇÏ¿©, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¾ÇÀÇÀûÀÎ PHP ÆÄÀϵéÀ» IncludeÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. Register_globals ¼³Á¤ÀÌ 'on'À¸·Î ¼³Á¤µÇ¾î ÀÖ´Ù¸é ÀÌ Ãë¾àÁ¡Àº µµ¿ëµÉ ¼ö ÀÖ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ Àß Á¶ÀÛµÈ URL ¿äûÀ» º¸³» ´ë»ó ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ PHP ÄÚµå¿Í ¿î¿µÃ¼Á¦ ¸í·ÉµéÀ» ½ÇÇàÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.frsirt.com/english/advisories/2005/2473
http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0520.html
http://secunia.com/advisories/17622/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Miro International Pty »ç, Mambo Open Source 4.5.2.3 ÀÌÇÏÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ MamboForge À¥ »çÀÌÆ®ÀÎ http://sourceforge.net/projects/mambo/ ¿¡¼­ 4.6.2ÀÌ»ó ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2005-3738 (CVE)
°ü·Ã URL 15461 (SecurityFocus)
°ü·Ã URL 23146 (ISS)