English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21869
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç Mambo Open Source´Â 4.5.3h¿Í ±× ÀÌÀüÀÇ ¹öÀüµé¿¡ Á¸ÀçÇÏ´Â ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. Mambo Open Source(¿¹Àü¿¡´Â Mambo Site Server·Î ºÒ¸²)´Â ÀÎÅÍ³Ý Æ÷ÅÐ ¹× ÄÜÅÙÃ÷ °ü¸® ¼ÒÇÁÆ®¿þ¾îÀÌ´Ù. Mambo Open Source 4.5.3°ú 4.5.3h, ±×¸®°í ÀÌÀüÀÇ ¹öÀüµéÀº ÆÄÀϷκÎÅÍ PHP Äڵ带 Æ÷ÇÔ(Include)Çϵµ·Ï ÇÑ ÀÔ·ÂÀ» »ç¿ëÇϱâ Àü¿¡ 'mos_user_template' Cookie·ÎÀÇ ÀԷ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ °ËÁõÀ¸·Î ÀÎÇÏ¿©, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¿µÇâÀ» ¹Þ´Â È£½ºÆ® »ó¿¡ ÀÖ´Â ÀÓÀÇÀÇ ÆÄÀϵéÀ» º¸°Å³ª ÀÓÀÇÀÇ PHP Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ÀÌ °áÇÔ¿¡ ´õÇÏ¿©, ¹®Á¦ÀÇ ¼ÒÇÁÆ®¿þ¾îµéÀº ¶ÇÇÑ ´ÙÁßÀÇ SQL ÁÖÀÔ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ¸¸¾à magic_quotes_gpc ¼³Á¤ÀÌ »ç¿ë ¾ÈÇÔÀ¸·Î µÇ¾î ÀÖ´Ù¸é, 'includes/mambo.php' ½ºÅ©¸³Æ®¿¡ ÀÖ´Â 'username' Àμö, 'index2.php' ½ºÅ©¸³Æ®¿¡ ÀÖ´Â 'task' Àμö, ±×¸®°í 'components/com_content/content.php' ½ºÅ©¸³Æ®¿¡ ÀÖ´Â 'filter' Àμö·Î Àå Á¶ÀÛµÈ SQL ¹®ÀåµéÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡µéÀ» µµ¿ëÇÏ¿© ±â¹Ý µ¥ÀÌÅͺ£À̽º¿¡ ÀÖ´Â Á¤º¸¸¦ Ãß°¡, Á¶ÀÛ, »èÁ¦ÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.gulftech.org/?node=research&article_id=00104-02242006
http://archives.neohapsis.com/archives/bugtraq/2006-02/0463.html
http://secunia.com/advisories/18935/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Miro International Pty »ç, Mambo Open Source 4.5.3°ú 4.5.3h, ±×¸®°í ÀÌÀüÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ ´ÙÀ½ »çÀÌÆ®¸¦ Âü°íÇÏ¿© ÃֽŹöÀüÀÇ Mambo·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù.
http://sourceforge.net/projects/mambo/
°ü·Ã URL CVE-2006-0871 (CVE)
°ü·Ã URL 16775 (SecurityFocus)
°ü·Ã URL 24870 (ISS)