Ãë¾àÁ¡ID |
21918 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç Calendarix Advanced´Â 1.5 ÀÌÇÏÀÇ ¹öÀüµé¿¡ Á¸ÀçÇÏ´Â ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. Calendarix´Â PHP·Î Á¦ÀÛµÈ À¥ ±â¹ÝÀÇ ´Þ·Â ¾îÇø®ÄÉÀ̼ÇÀÌ´Ù. Calendarix Advanced ¹öÀü 1.5¿Í ±× ÀÌÀüÀÇ ¹öÀüµéÀº ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ¿¡ ÀÇÇØ Cross-Site Scripting, SQL ÁÖÀÔ, ±×¸®°í ·ÎÄà ÆÄÀÏ Include °ø°ÝµéÀ» ¼öÇàÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡µéÀ» ¼º°øÀûÀ¸·Î µµ¿ëÇÏ°Ô µÇ¸é °¡Àå ½É°¢ÇÑ °æ¿ì °ø°ÝÀÚ´Â ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ ½Ã½ºÅÛ ¸í·ÉµéÀ» ½ÇÇà½Ãų ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.calendarix.com/download_advanced.php http://www.calendarix.com/download_basic.php http://archives.neohapsis.com/archives/bugtraq/2005-05/0356.html http://www.osvdb.org/16971 http://www.osvdb.org/16972 http://www.osvdb.org/16973 http://www.osvdb.org/16974 http://www.osvdb.org/16975 http://securitytracker.com/alerts/2005/May/1014083.html http://secunia.com/advisories/15569
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Vincent Hor, Calendarix Advanced ¹öÀü 1.5¿Í ±× ÀÌÀüÀÇ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
Calendarix À¥ »çÀÌÆ®ÀÎ http://www.calendarix.com/download_advanced.php ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â Calendarix AdvancedÀÇ °¡Àå ÃֽŠ¹öÀü(1.6.20060126 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2005-1864,CVE-2005-1865,CVE-2005-1866 (CVE) |
°ü·Ã URL |
13825,13826 (SecurityFocus) |
°ü·Ã URL |
20827 (ISS) |
|