Ãë¾àÁ¡ID |
21798 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç Land Down Under (LDU)´Â 802 ÀÌÀüÀÇ ¹öÀüµé¿¡ Á¸ÀçÇÏ´Â ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. Land Down Under´Â PHP·Î Á¦ÀÛµÈ À¥ »çÀÌÆ® ÄÜÅÙÆ® °ü¸® ½Ã½ºÅÛ(CMS)ÀÌ´Ù. Land Down Under 801 ÀÌÇÏ ¹öÀüµéÀº ´ÙÁßÀÇ ÀÔ·Â °ËÁõ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀڵ鿡 ÀÇÇØ Cross-Site Scripting ±×¸®°í SQL ÁÖÀÔ °ø°ÝµéÀ» ¼öÇàÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.
1) ´ÙÁßÀÇ SQL ÁÖÀÔ Ãë¾àÁ¡µé: "index.php" ½ºÅ©¸³Æ®, 'list.php' ½ºÅ©¸³Æ®¿Í 'event.php' ½ºÅ©¸³Æ®ÀÇ ¿©·¯ Àμöµé·Î °Ç³×Áø ÀÔ·ÂÀº SQL ÁúÀǹ®À¸·Î »ç¿ëµÇ±â Àü¿¡ ÀûÀýÇÏ°Ô ÇÊÅ͸µµÇÁö ¾Ê´Â´Ù. ÀÌ°ÍÀº ÀÓÀÇÀÇ SQL Äڵ带 ÁÖÀÔÇÔÀ¸·Î½á SQL ÁúÀǵéÀ» Á¶ÀÛÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù. 2) ´ÙÁßÀÇ Cross-Site Scripting Ãë¾àÁ¡µé: 'index.php' ½ºÅ©¸³Æ®ÀÇ 'c'¿Í 'm' Àμöµé°ú 'journal.php' ½ºÅ©¸³Æ®ÀÇ 'w' Àμö·Î °Ç³×Áø ÀÔ·ÂÀº »ç¿ëµÇ±â Àü¿¡ ÀûÀýÇÏ°Ô ÇÊÅ͸µÀÌ µÇÁö ¾Ê´Â´Ù. ÀÌ Ãë¾àÁ¡Àº ÀÓÀÇÀÇ HTML°ú ½ºÅ©¸³Æ® Äڵ带 ÁÖÀÔÇϴµ¥ µµ¿ëµÉ ¼ö ÀÖÀ¸¸ç ÀÌ´Â ¾ÇÀÇÀûÀÎ »ç¿ëÀÚ µ¥ÀÌÅÍ°¡ º¸¿©Áö´Â ½ÃÁ¡¿¡ ¿µÇâÀ» ¹Þ´Â »çÀÌÆ®ÀÇ È¯°æ ÇÏ¿¡¼ »ç¿ëÀÚÀÇ ºê¶ó¿ìÀú ¼¼¼ÇÀ¸·Î ½ÇÇàµÈ´Ù.
* Âü°í »çÀÌÆ®: http://securityfocus.com/archive/1/409511 http://www.securitytracker.com/alerts/2005/Aug/1014747.html http://secunia.com/advisories/16710
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Neocrome Services, Land Down Under ¹öÀü 801°ú ±× ÀÌÀüÀÇ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
Land Down Under À¥ »çÀÌÆ®ÀÎ http://www.neocrome.net ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â Land Down UnderÀÇ °¡Àå ÃֽŠ¹öÀü(802 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2005-2788,CVE-2005-2884 (CVE) |
°ü·Ã URL |
14685,14746,14820 (SecurityFocus) |
°ü·Ã URL |
22195,21952,22047 (ISS) |
|