Ãë¾àÁ¡ID |
21925 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç Geeklog ¾îÇø®ÄÉÀ̼ÇÀº FCKeditor ÆÄÀÏ °ü¸®ÀÚ¿¡ ÀÖ´Â ÀÓÀÇÀÇ ÆÄÀÏ ¾÷·Îµå Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Weblog·Î Àß ¾Ë·ÁÁø Geeklog´Â µ¿Àû À¥ ÄÁÅÙÃ÷¸¦ °ü¸®Çϴµ¥ ¾²ÀÌ´Â PHP/MySQL ±â¹ÝÀÇ ¾îÇø®ÄÉÀ̼ÇÀÌ´Ù. Geeklog ¹öÀü 1.4.0sr3°ú ±× ÀÌÀüÀÇ ¹öÀüµéÀº ¿ø°ÝÁö °ø°ÝÀÚ°¡ /fckeditor/editor/filemanager/browser/mcpuk/connectors/php/connector.php ½ºÅ©¸³Æ®¸¦ ÅëÇØ ¿µÇâÀ» ¹Þ´Â È£½ºÆ® »óÀÇ "images/library/File" µð·ºÅ丮¿¡ ¾ÇÀÇÀûÀÎ PHP ÆÄÀϵéÀ» ¾÷·ÎµåÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¿ø°ÝÁö °ø°ÝÀÚ´Â Ãë¾àÇÑ ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇϴµ¥ ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÒ ¼ö ÀÖ´Ù. ¼º°øÀûÀ¸·Î µµ¿ëÇϱâ À§Çؼ´Â Apache ¼¹ö¿¡ "mod_mime" ¸ðµâ¿¡ ¼³Ä¡µÇ¾î ÀÖ¾î¾ß ÇÑ´Ù.
* Âü°í »çÀÌÆ®: http://www.geeklog.net/article.php/exploit-for-fckeditor-filemanager http://www.geeklog.net/article.php/geeklog-1.4.0sr4 http://secunia.com/advisories/20886/
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Geeklog ¹öÀü 1.4.0sr3°ú ±× ÀÌÀüÀÇ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
Geeklog À¥ »çÀÌÆ®ÀÎ http://www.geeklog.net/filemgmt/index.php?id=727 ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â GeeklogÀÇ °¡Àå ÃֽŠ¹öÀü(1.4.0sr4 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2006-3362 (CVE) |
°ü·Ã URL |
18767 (SecurityFocus) |
°ü·Ã URL |
27494 (ISS) |
|