Ãë¾àÁ¡ID |
21914 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç Pixelpost ÇÁ·Î±×·¥Àº 1.5-beta1 ÀÌÇÏÀÇ ¹öÀüµé¿¡ Á¸ÀçÇÏ´Â ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. Pixelpost´Â PHP¿Í MySQL¿¡ ±â¹ÝÀ» µÐ »çÁø ºí·Î±×(BLOG) ¾îÇø®ÄÉÀ̼ÇÀÌ´Ù. Pixelpost 1.4.3 ÀÌÇÏÀÇ ¹öÀüµé°ú 1.5-beta1 ÀÌÇÏÀÇ ¹öÀüµéÀº ´ÙÁßÀÇ ÀÔ·Â °ËÁõ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ¿¡ ÀÇÇØ SQL ÁÖÀÔ °ø°ÝµéÀ» ¼öÇàÇϰųª °ø°ÝÀÚ°¡ ¾ÇÀÇÀûÀÎ ½ºÅ©¸³Æ®µéÀ» ¾÷·ÎµåÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ÀÎÅÍÆäÀ̽º¿¡ ´ëÇÑ ºñÀΰ¡µÈ ¾×¼¼½º¸¦ ¾ò¾î³»°Å³ª ȤÀº À¥ ¼¹öÀÇ ±ÇÇÑÀ» °¡Áö°í ÀÓÀÇÀÇ ¸í·ÉµéÀ» ½ÇÇàÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù. ÀÌ¿¡ ´õÇÏ¿© ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â "includes/phpinfo.php" ½ºÅ©¸³Æ®¸¦ ¾×¼¼½ºÇÔÀ¸·Î½á "phpinfo()" ÇÔ¼ö¿¡ ÀÇÇØ ¹ÝȯµÈ ½Ã½ºÅÛ Á¤º¸ ¶ÇÇÑ ¾ò¾î³¾ ¼ö ÀÖ´Ù. ÀÌ Á¤º¸´Â º¸´Ù ´õ Á¤¹ÐÇÑ °ø°Ýµé¿¡ µµ¿òÀ» ÁÙ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://forum.pixelpost.org/showthread.php?t=3535 http://www.securityfocus.com/archive/1/426764/30/0/threaded http://www.neosecurityteam.net/index.php?action=advisories&id=19
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Pixelpost 1.4.3 ÀÌÇÏÀÇ ¹öÀüµé Pixelpost 1.5-beta 1 ÀÌÇÏÀÇ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
Pixelpost À¥ »çÀÌÆ®ÀÎ http://www.pixelpost.org/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â PixelpostÀÇ °¡Àå ÃֽŠ¹öÀü(1.5 RC1 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2006-1104,CVE-2006-1105,CVE-2006-1106 (CVE) |
°ü·Ã URL |
16964 (SecurityFocus) |
°ü·Ã URL |
25044,25046,25047,25048 (ISS) |
|