Ãë¾àÁ¡ID |
21892 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç PHPlist´Â $database_module º¯¼ö¸¦ ÅëÇÑ ·ÎÄà ÆÄÀÏ Æ÷ÇÔ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. PHPlist´Â ¸ÞÀϸµ ¸®½ºÆ® °ü¸®ÀÚÀÌÀÚ CRM(customer relationship management) ½Ã½ºÅÛÀ» ±¸ÇöÇÑ PHP·Î Á¦ÀÛµÈ À¥ ¾îÇø®ÄÉÀ̼ÇÀÌ´Ù. PHPlist ¹öÀü 2.10.2¿Í ±× ÀÌÀüÀÇ ¹öÀüµéÀº 'lists/index.php' ½ºÅ©¸³Æ®ÀÇ $database_module ȤÀº $language_module º¯¼ö·Î Àü´ÞµÈ »ç¿ëÀÚ°¡ Á¦°øÇÑ ÀԷ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ °ËÁõÀ¸·Î ÀÎÇÏ¿©, ·ÎÄà ÆÄÀÏ Æ÷ÇÔ(Include) Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. ¸¸¾à 'register_globals' ¼³Á¤ÀÌ »ç¿ëÇÔÀ¸·Î µÇ¾î ÀÖ´Ù¸é ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡µéÀ» µµ¿ëÇÏ¿© À¥ ¼¹ö ÇÁ·Î¼¼½ºÀÇ ±ÇÇÑÀ¸·Î °¡Áö°í ÀÓÀÇÀÇ ÆÄÀϵéÀ» º¸°Å³ª Ãë¾àÇÑ ½Ã½ºÅÛ »ó¿¡ ÀÖ´Â ÀÓÀÇÀÇ PHP ½ºÅ©¸³Æ® Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/archive/1/430475/30/30/threaded http://www.securityfocus.com/archive/1/430597 http://www.hardened-php.net/advisory_202005.79.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Open Source, PHPlist ¹öÀü 2.10.2¿Í ±× ÀÌÀüÀÇ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
PHPlist À¥ »çÀÌÆ®ÀÎ http://www.phplist.com/files/ ¿¡¼ ÃֽŹöÀüÀÇ PHPlist·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
´ÙÀ½ Hardened PHP Project Advisory 20/2005¿¡ ¼³¸íµÇ¾î ÀÖµíÀÌ PHPÀÇ °¡Àå ÃֽŠ¹öÀü(4.4.1 ȤÀº 5.0.5 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.hardened-php.net/advisory_202005.79.html |
°ü·Ã URL |
CVE-2006-1746 (CVE) |
°ü·Ã URL |
17429 (SecurityFocus) |
°ü·Ã URL |
25701 (ISS) |
|