English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21892
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç PHPlist´Â $database_module º¯¼ö¸¦ ÅëÇÑ ·ÎÄà ÆÄÀÏ Æ÷ÇÔ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. PHPlist´Â ¸ÞÀϸµ ¸®½ºÆ® °ü¸®ÀÚÀÌÀÚ CRM(customer relationship management) ½Ã½ºÅÛÀ» ±¸ÇöÇÑ PHP·Î Á¦ÀÛµÈ À¥ ¾îÇø®ÄÉÀ̼ÇÀÌ´Ù. PHPlist ¹öÀü 2.10.2¿Í ±× ÀÌÀüÀÇ ¹öÀüµéÀº 'lists/index.php' ½ºÅ©¸³Æ®ÀÇ $database_module ȤÀº $language_module º¯¼ö·Î Àü´ÞµÈ »ç¿ëÀÚ°¡ Á¦°øÇÑ ÀԷ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ °ËÁõÀ¸·Î ÀÎÇÏ¿©, ·ÎÄà ÆÄÀÏ Æ÷ÇÔ(Include) Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. ¸¸¾à 'register_globals' ¼³Á¤ÀÌ »ç¿ëÇÔÀ¸·Î µÇ¾î ÀÖ´Ù¸é ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡µéÀ» µµ¿ëÇÏ¿© À¥ ¼­¹ö ÇÁ·Î¼¼½ºÀÇ ±ÇÇÑÀ¸·Î °¡Áö°í ÀÓÀÇÀÇ ÆÄÀϵéÀ» º¸°Å³ª Ãë¾àÇÑ ½Ã½ºÅÛ »ó¿¡ ÀÖ´Â ÀÓÀÇÀÇ PHP ½ºÅ©¸³Æ® Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/430475/30/30/threaded
http://www.securityfocus.com/archive/1/430597
http://www.hardened-php.net/advisory_202005.79.html


* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Open Source, PHPlist ¹öÀü 2.10.2¿Í ±× ÀÌÀüÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ PHPlist À¥ »çÀÌÆ®ÀÎ http://www.phplist.com/files/ ¿¡¼­ ÃֽŹöÀüÀÇ PHPlist·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

´ÙÀ½ Hardened PHP Project Advisory 20/2005¿¡ ¼³¸íµÇ¾î ÀÖµíÀÌ PHPÀÇ °¡Àå ÃֽŠ¹öÀü(4.4.1 ȤÀº 5.0.5 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.hardened-php.net/advisory_202005.79.html
°ü·Ã URL CVE-2006-1746 (CVE)
°ü·Ã URL 17429 (SecurityFocus)
°ü·Ã URL 25701 (ISS)