English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21796
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç Exponent CMS ÇÁ·Î±×·¥Àº 0.96.4 ÀÌÀüÀÇ ¹öÀüµé¿¡ Á¸ÀçÇÏ´Â ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. Exponent CMS´Â PHP·Î Á¦ÀÛµÈ °ø°³ ¼Ò½º À¥ ±â¹ÝÀÇ ÄÜÅÙÆ® °ü¸® ½Ã½ºÅÛ(CMS) ÀÌ´Ù. Exponent CMS ¹öÀü 0.96.3°ú ±× ÀÌÀüÀÇ ¹öÀüµéÀº ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ¿¡ ÀÇÇØ SQL ÁÖÀÔ, Cross-Site Scripting ±×¸®°í ½ºÅ©¸³Æ® ÁÖÀÔ °ø°ÝµéÀ» ¼öÇàÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù. ÀÌ °áÇԵ鿡 ´õÇÏ¿© ¿ø°ÝÁöÀÇ Àΰ¡µÈ °ø°ÝÀÚ´Â ÀÚü À̹ÌÁö ¾÷·Îµå ¼³ºñ¸¦ ÅëÇØ ÀÓÀÇÀÇ PHP Äڵ带 °¡Áø ÆÄÀϵéÀ» ¾÷·ÎµåÇÏ°í À¥ ¼­¹ö ÇÁ·Î¼¼¼­ÀÇ ±ÇÇÑÀ¸·Î ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡ ±× Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://sourceforge.net/tracker/index.php?func=detail&aid=1230208&group_id=118524&atid=681366
http://sourceforge.net/tracker/index.php?func=detail&aid=1230221&group_id=118524&atid=681366
http://sourceforge.net/tracker/index.php?func=detail&aid=1353361&group_id=118524&atid=681366
http://archives.neohapsis.com/archives/bugtraq/2005-11/0243.html
http://secunia.com/advisories/17505/
http://secunia.com/advisories/17655/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
James Hunt and the OIC Group »ç, Exponent CMS ¹öÀü 0.96.3°ú ±× ÀÌÀüÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ SourceForge.net Downloads À¥ »çÀÌÆ®ÀÎ http://sourceforge.net/project/showfiles.php?group_id=118524 ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â Exponent CMSÀÇ °¡Àå ÃֽŠ¹öÀü(0.96.4 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2005-3761,CVE-2005-3762,CVE-2005-3763,CVE-2005-3764,CVE-2005-3765,CVE-2005-3766,CVE-2005-3767 (CVE)
°ü·Ã URL 15389,15391 (SecurityFocus)
°ü·Ã URL 23154,23155,23156,23157,23158 (ISS)