English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21868
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç CuteNews´Â 'archive' Àμö¸¦ ÅëÇÑ µð·ºÅ丮 Ž»ö Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. CutePHP CuteNews´Â µ¥ÀÌÅͺ£À̽º·ÎÀÇ ÀúÀå ÇüÅ·Π°³º° ÆÄÀϵéÀ» »ç¿ëÇÏ´Â PHP ±â¹ÝÀÇ ´º½º °ü¸® ¼ÒÇÁÆ®¿þ¾î·Î¼­ ¹«·á·Î »ç¿ë °¡´ÉÇÏ´Ù. CutePHP CuteNews ¹öÀü 1.4.1°ú ±× ÀÌÀüÀÇ ¹öÀüµéÀº inc/function.php ½ºÅ©¸³Æ®¿¡ ÀÖ´Â µð·ºÅ丮 Ž»ö Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. 'archive' Àμö¿¡ "dot dot" ½ÃÄö½ºµé(/../)À» Æ÷ÇÔÇÏ´Â inc/function.php ½ºÅ©¸³Æ®·ÎÀÇ Àß Á¶ÀÛµÈ HTTP POST ȤÀº COOKIE ¿äûÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ ÀÎÁõ¹ÞÁö ¾ÊÀº °ø°ÝÀÚ´Â À¥ ¼­ºñ½ºÀÇ ±ÇÇÑÀ» °¡Áö°í À¥ root µð·ºÅ丮 ¿ÜºÎÀÇ ÀÓÀÇÀÇ ÆÄÀϵéÀ» º¼ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://secunia.com/advisories/19289/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
CutePHP CuteNews ¹öÀü 1.4.1°ú ±× ÀÌÀüÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ CutePHP À¥ »çÀÌÆ®ÀÎ http://cutephp.com/cutenews/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â CuteNewsÀÇ °¡Àå ÃֽŠ¹öÀü(1.4.2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2006-1339,CVE-2006-1340 (CVE)
°ü·Ã URL 17152 (SecurityFocus)
°ü·Ã URL 25324 (ISS)