Ãë¾àÁ¡ID |
21982 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç Dokeos ÇÁ·Î±×·¥Àº 'extAuthSource' Àμö¸¦ ÅëÇÑ ¿ø°Ý ÆÄÀÏ Æ÷ÇÔ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Dokeos´Â ÇнÀ °ü¸® ½Ã½ºÅÛÀÌ´Ù. Dokeos 1.6.5 ÀÌÇÏÀÇ ¹öÀüµé°ú Dokeos Community Release 2.x ¹öÀüµéÀº 'claro_init_local.inc.php' ½ºÅ©¸³Æ®ÀÇ 'extAuthSource[newUser]' Àμö·Î Àü´ÞµÈ »ç¿ëÀÚ°¡ Á¦°øÇÑ ÀԷ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ °ËÁõÀ¸·Î ÀÎÇÏ¿©, ¿ø°Ý ÆÄÀÏ Æ÷ÇÔ(Include) Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â Àß Á¶ÀÛµÈ URL ¿äûÀ» º¸³» ¿µÇâÀ» ¹Þ´Â È£½ºÆ® »ó¿¡ ÀÓÀÇÀÇ PHP ÄÚµå¿Í ¿î¿µÃ¼Á¦ ¸í·ÉµéÀ» ½ÇÇàÇÒ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.gulftech.org/?node=research&article_id=00112-09142006 http://secunia.com/advisories/21931 http://secunia.com/advisories/21948
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Dokeos ¹öÀü 1.6.5¿Í ±× ÀÌÀüÀÇ ¹öÀüµé Dokeos Community Release 2.x ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
Dokeos ÇнÀ °ü¸® ½Ã½ºÅÛ À¥ »çÀÌÆ®ÀÎ http://www.dokeos.com/download.php ¿¡¼ ÃֽŹöÀüÀÇ Dokeos(1.8ÀÌ»ó)·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î´Â, PHPÀÇ 'register_globals' ¼³Á¤À» »ç¿ë ÁßÁöÇØ ³õ´Â´Ù. |
°ü·Ã URL |
CVE-2006-4844 (CVE) |
°ü·Ã URL |
20056 (SecurityFocus) |
°ü·Ã URL |
28943 (ISS) |
|