English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21876
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç Clever Copy´Â admin/connect.inc ÆÄÀÏÀ» ÅëÇÑ Á¤º¸ ³ëÃâ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Clever Copy´Â PHP·Î Á¦ÀÛµÈ ¹«·á·Î »ç¿ë °¡´ÉÇÑ À¥ Æ÷ÅÐ ¹× ´º½º Æ÷½ºÆà ½Ã½ºÅÛÀÌ´Ù. Clever Copy ¹öÀü 3.0°ú ±× ÀÌÀüÀÇ ¹öÀüµéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ 'admin/connect.inc' Include ÆÄÀÏ¿¡ ´ëÇØ ¾×¼¼½ºÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â 'admin/connect.inc' ÆÄÀÏÀ» Á÷Á¢ÀûÀ¸·Î ¾×¼¼½ºÇÔÀ¸·Î½á µ¥ÀÌÅͺ£À̽º¿¡ Á¢¼ÓÇϱâ À§ÇØ ¾îÇø®ÄÉÀ̼ǿ¡ ÀÇÇØ »ç¿ëµÇ´Â µ¥ÀÌÅͺ£À̽º »ç¿ëÀÚ¸í°ú Æнº¿öµå¸¦ º¼ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/archive/1/430369/100/0/threaded
http://secunia.com/advisories/19579/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Clever Copy ¹öÀü 3.0°ú ±× ÀÌÀüÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ Clever Copy´Â ´õ ÀÌ»ó Áö¿øµÇÁö ¾Ê´Â´Ù. º¸¾ÈÀ» À§ÇØ ´Ù¸¥ ¼Ö·ç¼ÇÀ¸·Î ´ëüÇÒ °ÍÀ» ±Ç°íÇÑ´Ù.

Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î´Â, ".htaccess" ÆÄÀÏÀ» °¡Áö°í Clever CopyÀÇ admin µð·ºÅ丮¿¡ ´ëÇÑ ¾×¼¼½º¸¦ Á¦ÇÑÇÏ´Ù.
°ü·Ã URL CVE-2006-1718 (CVE)
°ü·Ã URL 17461 (SecurityFocus)
°ü·Ã URL 25720 (ISS)