English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21918
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç Calendarix Advanced´Â 1.5 ÀÌÇÏÀÇ ¹öÀüµé¿¡ Á¸ÀçÇÏ´Â ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. Calendarix´Â PHP·Î Á¦ÀÛµÈ À¥ ±â¹ÝÀÇ ´Þ·Â ¾îÇø®ÄÉÀ̼ÇÀÌ´Ù. Calendarix Advanced ¹öÀü 1.5¿Í ±× ÀÌÀüÀÇ ¹öÀüµéÀº ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ¿¡ ÀÇÇØ Cross-Site Scripting, SQL ÁÖÀÔ, ±×¸®°í ·ÎÄà ÆÄÀÏ Include °ø°ÝµéÀ» ¼öÇàÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡µéÀ» ¼º°øÀûÀ¸·Î µµ¿ëÇÏ°Ô µÇ¸é °¡Àå ½É°¢ÇÑ °æ¿ì °ø°ÝÀÚ´Â ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ ½Ã½ºÅÛ ¸í·ÉµéÀ» ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.calendarix.com/download_advanced.php
http://www.calendarix.com/download_basic.php
http://archives.neohapsis.com/archives/bugtraq/2005-05/0356.html
http://www.osvdb.org/16971
http://www.osvdb.org/16972
http://www.osvdb.org/16973
http://www.osvdb.org/16974
http://www.osvdb.org/16975
http://securitytracker.com/alerts/2005/May/1014083.html
http://secunia.com/advisories/15569

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Vincent Hor, Calendarix Advanced ¹öÀü 1.5¿Í ±× ÀÌÀüÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ Calendarix À¥ »çÀÌÆ®ÀÎ http://www.calendarix.com/download_advanced.php ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â Calendarix AdvancedÀÇ °¡Àå ÃֽŠ¹öÀü(1.6.20060126 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2005-1864,CVE-2005-1865,CVE-2005-1866 (CVE)
°ü·Ã URL 13825,13826 (SecurityFocus)
°ü·Ã URL 20827 (ISS)