English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21925
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç Geeklog ¾îÇø®ÄÉÀ̼ÇÀº FCKeditor ÆÄÀÏ °ü¸®ÀÚ¿¡ ÀÖ´Â ÀÓÀÇÀÇ ÆÄÀÏ ¾÷·Îµå Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Weblog·Î Àß ¾Ë·ÁÁø Geeklog´Â µ¿Àû À¥ ÄÁÅÙÃ÷¸¦ °ü¸®Çϴµ¥ ¾²ÀÌ´Â PHP/MySQL ±â¹ÝÀÇ ¾îÇø®ÄÉÀ̼ÇÀÌ´Ù. Geeklog ¹öÀü 1.4.0sr3°ú ±× ÀÌÀüÀÇ ¹öÀüµéÀº ¿ø°ÝÁö °ø°ÝÀÚ°¡ /fckeditor/editor/filemanager/browser/mcpuk/connectors/php/connector.php ½ºÅ©¸³Æ®¸¦ ÅëÇØ ¿µÇâÀ» ¹Þ´Â È£½ºÆ® »óÀÇ "images/library/File" µð·ºÅ丮¿¡ ¾ÇÀÇÀûÀÎ PHP ÆÄÀϵéÀ» ¾÷·ÎµåÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¿ø°ÝÁö °ø°ÝÀÚ´Â Ãë¾àÇÑ ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇϴµ¥ ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÒ ¼ö ÀÖ´Ù. ¼º°øÀûÀ¸·Î µµ¿ëÇϱâ À§Çؼ­´Â Apache ¼­¹ö¿¡ "mod_mime" ¸ðµâ¿¡ ¼³Ä¡µÇ¾î ÀÖ¾î¾ß ÇÑ´Ù.

* Âü°í »çÀÌÆ®:
http://www.geeklog.net/article.php/exploit-for-fckeditor-filemanager
http://www.geeklog.net/article.php/geeklog-1.4.0sr4
http://secunia.com/advisories/20886/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Geeklog ¹öÀü 1.4.0sr3°ú ±× ÀÌÀüÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ Geeklog À¥ »çÀÌÆ®ÀÎ http://www.geeklog.net/filemgmt/index.php?id=727 ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â GeeklogÀÇ °¡Àå ÃֽŠ¹öÀü(1.4.0sr4 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2006-3362 (CVE)
°ü·Ã URL 18767 (SecurityFocus)
°ü·Ã URL 27494 (ISS)