English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21793
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç FlatNuke ÇÁ·Î±×·¥Àº read ¸ðµâÀÇ id Àμö¸¦ ÅëÇÑ µð·ºÅ丮 Ž»ö Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. FlatNuke´Â µ¥ÀÌÅͺ£À̽º ´ë½Å¿¡ ÀÏ¹Ý ÅؽºÆ®¿¡¸¸ ÀÇÁ¸ÇÏ´Â PHP·Î Á¦ÀÛµÈ CMS(Content Management System)ÀÌ´Ù. FlatNuke 2.5.6À» Æ÷ÇÔÇÑ ´Ù¸¥ ¿©·¯ ¹öÀüµéÀº 'index.php' ½ºÅ©¸³Æ®ÀÇ 'id' Àμö·Î Àü´ÞµÈ »ç¿ëÀÚ Á¦°ø ÀԷ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ °ËÁõÀ¸·Î ÀÎÇÏ¿© ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ À¥ rootÀÇ ¿ÜºÎ¿¡ ÀÖ´Â µð·ºÅ丮µéÀ» Ž»öÇÏ°í ÆÄÀϵéÀ» º¼ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. "dot dot" ½ÃÄö½ºµé(../)°ú null ¹ÙÀÌÆ®(%00)¸¦ Æ÷ÇÔÇÑ Àß Á¶ÀÛµÈ URLÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â À¥ ¼­ºñ½ºÀÇ ±ÇÇÑÀ» °¡Áö°í À¥ root µð·ºÅ丮ÀÇ ¿ÜºÎ¿¡ ÀÖ´Â ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐ¾î ³¾ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/archive/1/419107/100/0/threaded
http://securitytracker.com/alerts/2005/Dec/1015339.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
FlatNuke SourceForge Project, FlatNuke 2.5.6À» Æ÷ÇÔÇÑ ´Ù¸¥ ¿©·¯ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ SourceForge.net À¥ »çÀÌÆ®ÀÎ http://prdownloads.sourceforge.net/flatnuke/ ¿¡¼­ ÃֽŹöÀüÀÇ FlatNuke(2.5.7 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î PHPÀÇ 'magic_quotes_gpc' ¼³Á¤À» »ç¿ë ÇÔÀ¸·Î ÀüȯÇÑ´Ù.
°ü·Ã URL CVE-2005-4208 (CVE)
°ü·Ã URL 15796 (SecurityFocus)
°ü·Ã URL (ISS)