English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21856
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç Loudblog ÇÁ·Î±×·¥Àº 0.42 ÀÌÀüÀÇ ¹öÀüµé¿¡ Á¸ÀçÇÏ´Â ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. Loudblog´Â PHP·Î ¸¸µé¾î Áø À¥ »ó¿¡¼­ ¿Àµð¿À ÄÜÅÙÆ®¸¦ Á¦ÀÛÇÒ ¼ö ÀÖ°Ô ÇØ ÁÖ´Â CMS(Content Management System)ÀÌ´Ù. Loudblog ¹öÀü 0.41°ú ±× ÀÌÀüÀÇ ¹öÀüµéÀº ´ÙÀ½°ú °°Àº ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù:

1) µð·ºÅ丮 Ž»ö Ãë¾àÁ¡µé: "index.php" ½ºÅ©¸³Æ®¿¡ ÀÖ´Â "template" Àμö·Î Àü´ÞµÈ ÀÔ·ÂÀº ÆÄÀϵéÀ» º¸´Â µ¥ »ç¿ëµÇ¾î Áö±â Àü¿¡ ÀûÀýÇÏ°Ô ÇÊÅ͸µµÇÁö ¾Ê´Â´Ù. ÀÌ´Â µð·ºÅ丮 Ž»ö °ø°ÝµéÀ» ÅëÇØ ÀÓÀÇÀÇ ÆÄÀϵéÀÇ ³»¿ëÀ» ³ëÃâ½ÃÅ°´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.
2) SQL ÁÖÀÔ Ãë¾àÁ¡: "podcast.php" ½ºÅ©¸³Æ®¿¡ ÀÖ´Â "id" Àμö·Î Àü´ÞµÈ ÀÔ·ÂÀº SQL ÁúÀÇ·Î »ç¿ëµÇ¾î Áö±â Àü¿¡ ÀûÀýÇÏ°Ô ÇÊÅ͸µµÇÁö ¾Ê´Â´Ù. ÀÌ´Â ÀÓÀÇÀÇ SQL Äڵ带 ÁÖÀÔÇÔÀ¸·Î½á SQL ÁúÀǵéÀ» Á¶ÀÛÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.
3) ·ÎÄà ÆÄÀÏ Include Ãë¾àÁ¡µé: ÀÌ´Â 'index.php' ½ºÅ©¸³Æ®¿¡ ÀÖ´Â 'template' ±×¸®°í 'page' Àμöµé, ±×¸®°í 'inc/backend_settings.php' ½ºÅ©¸³Æ®¿¡ ÀÖ´Â 'language' Àμö¿¡ .. (dot dot)¿Í ¸¶Áö¸·¿¡ µ¡ºÙ´Â %00 (NULL) ¹ÙÀÌÆ®¸¦ ÅëÇØ ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ÀÓÀÇÀÇ ÆÄÀÏÀ» Àаųª IncludeÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/426973/30/0/threaded
http://secunia.com/advisories/19172/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Loudblog ¹öÀü 0.41°ú ±× ÀÌÀüÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ Loudblog ´Ù¿î·Îµå À¥ »çÀÌÆ®ÀÎ http://loudblog.de/index.php?s=download ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â LoudblogÀÇ °¡Àå ÃֽŠ¹öÀü(0.42 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2006-1113,CVE-2006-1114 (CVE)
°ü·Ã URL 17023 (SecurityFocus)
°ü·Ã URL 25101,25103,25104 (ISS)