Ãë¾àÁ¡ID |
21797 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç phpCOIN ¼ÒÇÁÆ®¿þ¾î´Â ¹öÀü 1.2.2¿¡ Á¸ÀçÇÏ´Â ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. phpCOINÀº °í°´, ÁÖ¹®, ¼ÛÀå, ³ëÆ®, ÇïÇÁµ¥½ºÅ©µéÀ» Ãë±ÞÇÒ ¼ö ÀÖµµ·Ï À¥ È£½ºÆà ÆǸž÷ÀÚµéÀ» À§ÇØ °í¾ÈµÈ ¹«·á ¼ÒÇÁÆ®¿þ¾î ÆÐÅ°ÁöÀÌ´Ù. phpCOIN ¹öÀü 1.2.2´Â µÎ °³ÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ¿¡ ÀÇÇØ SQL ÁÖÀÔ °ø°ÝµéÀ» ¼öÇàÇÏ°í Ãë¾àÇÑ ½Ã½ºÅÛÀ» Àå¾ÇÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù:
1) "config.php"¿¡ ÀÖ´Â "_CCFG[_PKG_PATH_DBSE]" Àμö·Î Àü´ÞµÈ ÀÔ·ÂÀº ÆÄÀϵéÀ» Æ÷ÇÔ(Include)ÇÏ´Â µ¥ »ç¿ëµÇ±â Àü¿¡ ÀûÀýÇÏ°Ô °ËÁõµÇÁö ¾Ê´Â´Ù. ¸¸¾à register_globals ¼³Á¤ÀÌ »ç¿ëÇÔÀ¸·Î µÇ¾î ÀÖ´Ù¸é ¿ø°ÝÁöÀÇ ºñÀΰ¡µÈ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡µé µµ¿ëÇÏ¿© À¥ ¼¹ö ÇÁ·Î¼¼¼ÀÇ ±ÇÇÑÀ» °¡Áö°í Ãë¾àÇÑ ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐ¾î ³»°Å³ª ÀÓÀÇÀÇ PHP Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù. 2) "phpcoinsessid" ÄíÅ° Àμö·Î Àü´ÞµÈ ÀÔ·ÂÀº SQL ÁúÀÇ·Î »ç¿ëµÇ±â Àü¿¡ ÀûÀýÇÏ°Ô ÇÊÅ͸µµÇÁö ¾Ê´Â´Ù. ¸¸¾à magic_quotes_gpc ¼³Á¤ÀÌ »ç¿ë ¾ÈÇÔÀ¸·Î µÇ¾î ÀÖ´Ù¸é ÀÌ°ÍÀº ÀÓÀÇÀÇ SQL Äڵ带 ÁÖÀÔÇÔÀ¸·Î½á SQL ÁúÀǵéÀ» Á¶ÀÛÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://forums.phpcoin.com/index.php?showtopic=5469 http://secunia.com/advisories/18030 http://securitytracker.com/id?1015345 http://www.securityfocus.com/archive/1/archive/1/419382/100/0/threaded
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: phpCOIN ¹öÀü 1.2.2 ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
phpCOIN ´Ù¿î·Îµå À¥ »çÀÌÆ®ÀÎ http://www.phpcoin.com/auxpage.php?page=download ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â phpCOINÀÇ °¡Àå ÃֽŠ¹öÀü(2005-12-13 fix-fileÀ» °¡Áø 1.2.2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2005-4211,CVE-2005-4212,CVE-2005-4213 (CVE) |
°ü·Ã URL |
15830,15831 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|