English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21936
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç Joomla! ȤÀº Mambo´Â 'mosConfig_absolute_path' Àμö¿¡ ÀÖ´Â ¿ø°Ý ÆÄÀÏ Include Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Mambo Open Source(¿¹Àü¿¡´Â Mambo Site Server·Î ºÒ¸²)´Â ÀÎÅÍ³Ý Æ÷ÅÐ ¹× ÄÜÅÙÃ÷ °ü¸® ¼ÒÇÁÆ®¿þ¾îÀÌ´Ù. Joomla!´Â PHP·Î Á¦ÀÛµÈ °ø°³ ¼Ò½º ÄÜÅÙÆ® °ü¸® ½Ã½ºÅÛÀÌ´Ù. À̵é ÇÁ·Î±×·¥µéÀ» À§ÇÑ ÄÄÆ÷³ÍÆ®µéÀ̳ª ¸ðµâµéÀÇ ¸î¸î ¹öÀüµéÀº 'mosConfig_absolute_path' Àμö·Î Àü´ÞµÈ »ç¿ëÀÚ°¡ Á¦°øÇÑ ÀԷ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ °ËÁõÀ¸·Î ÀÎÇÏ¿©, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¾ÇÀÇÀûÀÎ PHP ÆÄÀϵéÀ» IncludeÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. register_globals ¼³Á¤ÀÌ 'on'À¸·Î ¼³Á¤µÇ¾î ÀÖ´Ù¸é ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ Àß Á¶ÀÛµÈ URL ¿äûÀ» º¸³» ´ë»ó ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ PHP ÄÚµå¿Í ¿î¿µÃ¼Á¦ ¸í·ÉµéÀ» ½ÇÇàÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://forum.mamboserver.com/showthread.php?t=83001
http://forum.joomla.org/index.php/topic,75390.msg402249.html#msg402249
http://extensions.joomla.org/component/option,com_mtree/task,viewlink/link_id,142/Itemid,35/
http://secunia.com/advisories/20949/


* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Joomla!¸¦ À§ÇÑ RsGallery2 ¹öÀü 1.11.2
Mambo¸¦ À§ÇÑ Galleria ¹öÀü 1.0
Joomla!¸¦ À§ÇÑ ExtCalendar ¹öÀü 2.0
Joomla!¸¦ À§ÇÑ pc_cookbook ¹öÀüµé 0.3, 1.3.1
Mambo¸¦ À§ÇÑ pc_cookbook ¹öÀüµé 0.3, 1.3.1
SMF¸¦ À§ÇÑ SMF Forum ¹öÀü 1.3
Joomla!¸¦ À§ÇÑ perForms ¹öÀü 1.0
Mambo¸¦ À§ÇÑ Sitemap ¹öÀü 2.0
MamboXChange¸¦ À§ÇÑ LoudMouth ¹öÀü 4.0j
MamboXChange¸¦ À§ÇÑ EXTCalendar ¹öÀüµé 0.9.1, 2.0
MamboXChange¸¦ À§ÇÑ HTMLArea3 addon - ImageManager ¹öÀü 1.5
MamboXChange¸¦ À§ÇÑ MultiBanner ¹öÀü 1.0.1
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ 2014³â 6¿ù ÇöÀç ¾÷±×·¹À̵峪 ÆÐÄ¡´Â ³ª¿Í ÀÖÁö ¾Ê´Ù. ¼Ò½º Äڵ带 ÆíÁýÇÏ¿© ÀÔ·ÂÀÌ ÀûÀýÇÏ°Ô °ËÁõµÇµµ·Ï ¼öÁ¤ÇÑ´Ù.

Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î´Â, PHPÀÇ 'register_globals' ¼³Á¤À» »ç¿ëÁßÁö ÇØ ³õ´Â´Ù.
°ü·Ã URL CVE-2006-3396,CVE-2006-3530,CVE-2006-3556 (CVE)
°ü·Ã URL 18876,18919,18924,18968,18991,19037,19042,19044,19047,19100 (SecurityFocus)
°ü·Ã URL 27418,27528,27633,27641,27724 (ISS)