English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21914
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç Pixelpost ÇÁ·Î±×·¥Àº 1.5-beta1 ÀÌÇÏÀÇ ¹öÀüµé¿¡ Á¸ÀçÇÏ´Â ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. Pixelpost´Â PHP¿Í MySQL¿¡ ±â¹ÝÀ» µÐ »çÁø ºí·Î±×(BLOG) ¾îÇø®ÄÉÀ̼ÇÀÌ´Ù. Pixelpost 1.4.3 ÀÌÇÏÀÇ ¹öÀüµé°ú 1.5-beta1 ÀÌÇÏÀÇ ¹öÀüµéÀº ´ÙÁßÀÇ ÀÔ·Â °ËÁõ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ¿¡ ÀÇÇØ SQL ÁÖÀÔ °ø°ÝµéÀ» ¼öÇàÇϰųª °ø°ÝÀÚ°¡ ¾ÇÀÇÀûÀÎ ½ºÅ©¸³Æ®µéÀ» ¾÷·ÎµåÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ÀÎÅÍÆäÀ̽º¿¡ ´ëÇÑ ºñÀΰ¡µÈ ¾×¼¼½º¸¦ ¾ò¾î³»°Å³ª ȤÀº À¥ ¼­¹öÀÇ ±ÇÇÑÀ» °¡Áö°í ÀÓÀÇÀÇ ¸í·ÉµéÀ» ½ÇÇàÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù. ÀÌ¿¡ ´õÇÏ¿© ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â "includes/phpinfo.php" ½ºÅ©¸³Æ®¸¦ ¾×¼¼½ºÇÔÀ¸·Î½á "phpinfo()" ÇÔ¼ö¿¡ ÀÇÇØ ¹ÝȯµÈ ½Ã½ºÅÛ Á¤º¸ ¶ÇÇÑ ¾ò¾î³¾ ¼ö ÀÖ´Ù. ÀÌ Á¤º¸´Â º¸´Ù ´õ Á¤¹ÐÇÑ °ø°Ýµé¿¡ µµ¿òÀ» ÁÙ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://forum.pixelpost.org/showthread.php?t=3535
http://www.securityfocus.com/archive/1/426764/30/0/threaded
http://www.neosecurityteam.net/index.php?action=advisories&id=19

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Pixelpost 1.4.3 ÀÌÇÏÀÇ ¹öÀüµé
Pixelpost 1.5-beta 1 ÀÌÇÏÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ Pixelpost À¥ »çÀÌÆ®ÀÎ http://www.pixelpost.org/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â PixelpostÀÇ °¡Àå ÃֽŠ¹öÀü(1.5 RC1 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2006-1104,CVE-2006-1105,CVE-2006-1106 (CVE)
°ü·Ã URL 16964 (SecurityFocus)
°ü·Ã URL 25044,25046,25047,25048 (ISS)