English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21995
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç phpMyAdmin ÇÁ·Î±×·¥Àº 2.9.0.1 ÀÌÀüÀÇ ¹öÀüµé¿¡ Á¸ÀçÇÏ´Â ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. phpMyAdmin´Â À¥À» ÅëÇØ MySQL¸¦ °ü¸®ÇÏ·Á´Â ¸ñÀûÀÇ PHP·Î Á¦ÀÛµÈ ÅøÀÌ´Ù. ÇöÀç ÀÌ ÅøÀº µ¥ÀÌÅͺ£À̽ºÀÇ »ý¼º°ú »èÁ¦, Å×À̺íÀÇ »ý¼º/»èÁ¦/º¯°æ, ÇʵåÀÇ »èÁ¦/ÆíÁý/Ãß°¡, ÀÓÀÇÀÇ SQL ¹®ÀÇ ½ÇÇà, Çʵå»óÀÇ Å° °ü¸® ±â´É µîÀ» Á¦°øÇÑ´Ù. phpMyAdmin 2.9.0.1 ÀÌÀüÀÇ ¹öÀüµéÀº ´ÙÀ½ ¹®Á¦µé¿¡ Ãë¾àÇÏ´Ù:

ù¹ø° °áÇÔÀº phpMyAdmin ¶óÀ̺귯¸®ÀÎ 'common.lib.php', 'session.inc.php'¿Í'url_generating.lib.php' ½ºÅ©¸³Æ® ³»¿¡ ÀÖ´Â ºÒ¸íÈ®ÇÑ Ãë¾àÁ¡ÀÌ´Ù. ÀÌ Ãë¾àÁ¡ÀÇ ¿øÀΰú ¿µÇâÀº ÇöÀç·Î¼­´Â ¾Ë·ÁÁ® ÀÖÁö ¾Ê´Ù.
µÎ¹ø° °áÇÔÀº ¿ø°ÝÁö °ø°ÝÀÚ°¡ Á¦ÇÑµÈ ÆÄÀÏ¿¡ ´ëÇØ ºñÀΰ¡µÈ Á¢±Ù ±ÇÇÑÀ» ȹµæÇÏ°Ô ÇØ ÁØ´Ù. ¿ø°ÝÁö °ø°ÝÀÚ´Â ¶óÀ̺귯¸® µð·ºÅ丮 ³»ÀÇ ÀÓÀÇÀÇ ÆÄÀϵ鿡 ´ëÇÑ ¿äûÀ» º¸³¿À¸·Î½á ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÒ ¼ö ÀÖ´Ù.
¼¼¹ø° °áÇÔÀº »ç¿ëÀÚ°¡ Á¦°øÇÑ ÀԷ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ °ËÁõÀ¸·Î ÀÎÇÑ Cross-Site Scripting °áÇÔÀÌ´Ù. ¿ø°ÝÁö °ø°ÝÀÚ´Â ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡¼­ SQL Äõ¸®¹®À» ½ÇÇàÇÏ´Â °ÍÀ¸·Î ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.hardened-php.net/advisory_072006.130.html
http://secunia.com/advisories/22126
http://archives.neohapsis.com/archives/fulldisclosure/2006-10/0006.html
http://www.securityfocus.com/archive/1/archive/1/447491/100/0/threaded

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Tobias Ratschiller, phpMyAdmin 2.9.0.1 ÀÌÀüÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ phpMyAdmin ´Ù¿î·Îµå À¥ ÆäÀÌÁöÀÎ http://www.phpmyadmin.net/home_page/downloads.php ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â phpMyAdminÀÇ °¡Àå ÃֽŠ¹öÀü(2.9.0.1 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2006-5116,CVE-2006-5117 (CVE)
°ü·Ã URL 20253 (SecurityFocus)
°ü·Ã URL 29329,29330,29301 (ISS)