Ãë¾àÁ¡ID |
21981 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç Dokeos ÇÁ·Î±×·¥Àº 1.6.4 ȤÀº 2.0.3 ÀÌÀüÀÇ ¹öÀüµé¿¡ Á¸ÀçÇÏ´Â ´ÙÁßÀÇ ÆÄÀÏ Æ÷ÇÔ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. Dokeos´Â ÇнÀ °ü¸® ½Ã½ºÅÛÀÌ´Ù. Dokeos 1.6.3 ÀÌÇÏÀÇ ¹öÀüµé°ú Dokeos Community Release 2.0.2 ÀÌÇÏÀÇ ¹öÀüµéÀº 'claroline/exercice/testheaderpage.php' ½ºÅ©¸³Æ®¿¡ ÀÖ´Â 'rootSys' Àμö ±×¸®°í 'claroline/resourcelinker/resourcelinker.inc.php' ½ºÅ©¸³Æ®¿¡ ÀÖ´Â 'clarolineRepositorySys' Àμö·Î Àü´ÞµÈ »ç¿ëÀÚ°¡ Á¦°øÇÑ ÀԷ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ °ËÁõÀ¸·Î ÀÎÇÏ¿©, ´ÙÁßÀÇ ¿ø°Ý ÆÄÀÏ Æ÷ÇÔ(Include) Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ¸¸¾à PHPÀÇ 'register_globals' ¼³Á¤ÀÌ »ç¿ë ÇÔÀ¸·Î µÇ¾î ÀÖ´Ù¸é, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â Àß Á¶ÀÛµÈ URL ¿äûÀ» º¸³» ¿µÇâÀ» ¹Þ´Â È£½ºÆ® »ó¿¡ ÀÓÀÇÀÇ PHP ÄÚµå¿Í ¿î¿µÃ¼Á¦ ¸í·ÉµéÀ» ½ÇÇàÇÒ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.dokeos.com/forum/viewtopic.php?t=6848 http://www.dokeos.com/wiki/index.php/Security#April_5th.2C_2006 http://secunia.com/advisories/19576/
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Dokeos ¹öÀü 1.6.3°ú ±× ÀÌÀüÀÇ ¹öÀüµé Dokeos ¹öÀü 2.0.2¿Í ±× ÀÌÀüÀÇ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
Dokeos ÇнÀ °ü¸® ½Ã½ºÅÛ À¥ »çÀÌÆ®ÀÎ http://www.dokeos.com/download.php ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â Dokeos (1.6.4 ȤÀº ÀÌÈÄ) ȤÀº Dokeos Community Release (2.0.3 ȤÀº ÀÌÈÄ)ÀÇ °¡Àå ÃֽŠ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2006-2286 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
25740 (ISS) |
|