Ãë¾àÁ¡ID |
21974 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç e107 À¥»çÀÌÆ® ½Ã½ºÅÛÀº 'e107_handlers/tiny_mce/plugins/ibrowser/ibrowser.php' ½ºÅ©¸³Æ®¸¦ ÅëÇÑ ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. e107Àº ¹«·á·Î »ç¿ë °¡´ÉÇÑ PHP·Î Á¦ÀÛµÈ À¥ ÄÜÅÙÆ® °ü¸® ½Ã½ºÅÛÀÌ´Ù. PHP 4.0¿¡¼ 4.4.0±îÁöÀÇ ¹öÀüµé°ú 5.0¿¡¼ 5.0.5±îÁöÀÇ ¹öÀüµéÀº 'ibrowser.php' ½ºÅ©¸³Æ®³ª extract() ȤÀº import_request_variables() ÇÔ¼ö ³»ÀÇ Ãë¾àÁ¡À¸·Î ÀÎÇÏ¿© ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡¼ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. ¸¸¾à register_globals ¿É¼ÇÀÌ »ç¿ëÇÔÀ¸·Î µÇ¾î ÀÖ´Ù¸é, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â 'GLOBALS' ÆÄÀÏ ¾÷·Îµå Çʵ带 °¡Áø multipart/form-data POST ¿äûÀ» º¸³» ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ PHP Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0647.html http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0934.html http://www.gentoo.org/security/en/glsa/glsa-200511-08.xml https://rhn.redhat.com/errata/RHSA-2005-831.html https://rhn.redhat.com/errata/RHSA-2005-838.html http://secunia.com/advisories/17371/ http://www.securityfocus.com/archive/1/archive/1/415290/30/0/threaded
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: PHP 4.0¿¡¼ 4.4.0±îÁöÀÇ ¹öÀüµé PHP 5.0¿¡¼ 5.0.5±îÁöÀÇ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
PHP À¥ »çÀÌÆ®ÀÎ http://www.php.net/downloads.php ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â PHPÀÇ °¡Àå ÃֽŠ¹öÀü(4.4.3 ȤÀº ÀÌÈÄ, ȤÀº 5.1.4 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2005-3390,CVE-2006-3017 (CVE) |
°ü·Ã URL |
15250,17843 (SecurityFocus) |
°ü·Ã URL |
22920 (ISS) |
|