Ãë¾àÁ¡ID |
21995 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç phpMyAdmin ÇÁ·Î±×·¥Àº 2.9.0.1 ÀÌÀüÀÇ ¹öÀüµé¿¡ Á¸ÀçÇÏ´Â ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. phpMyAdmin´Â À¥À» ÅëÇØ MySQL¸¦ °ü¸®ÇÏ·Á´Â ¸ñÀûÀÇ PHP·Î Á¦ÀÛµÈ ÅøÀÌ´Ù. ÇöÀç ÀÌ ÅøÀº µ¥ÀÌÅͺ£À̽ºÀÇ »ý¼º°ú »èÁ¦, Å×À̺íÀÇ »ý¼º/»èÁ¦/º¯°æ, ÇʵåÀÇ »èÁ¦/ÆíÁý/Ãß°¡, ÀÓÀÇÀÇ SQL ¹®ÀÇ ½ÇÇà, Çʵå»óÀÇ Å° °ü¸® ±â´É µîÀ» Á¦°øÇÑ´Ù. phpMyAdmin 2.9.0.1 ÀÌÀüÀÇ ¹öÀüµéÀº ´ÙÀ½ ¹®Á¦µé¿¡ Ãë¾àÇÏ´Ù:
ù¹ø° °áÇÔÀº phpMyAdmin ¶óÀ̺귯¸®ÀÎ 'common.lib.php', 'session.inc.php'¿Í'url_generating.lib.php' ½ºÅ©¸³Æ® ³»¿¡ ÀÖ´Â ºÒ¸íÈ®ÇÑ Ãë¾àÁ¡ÀÌ´Ù. ÀÌ Ãë¾àÁ¡ÀÇ ¿øÀΰú ¿µÇâÀº ÇöÀç·Î¼´Â ¾Ë·ÁÁ® ÀÖÁö ¾Ê´Ù. µÎ¹ø° °áÇÔÀº ¿ø°ÝÁö °ø°ÝÀÚ°¡ Á¦ÇÑµÈ ÆÄÀÏ¿¡ ´ëÇØ ºñÀΰ¡µÈ Á¢±Ù ±ÇÇÑÀ» ȹµæÇÏ°Ô ÇØ ÁØ´Ù. ¿ø°ÝÁö °ø°ÝÀÚ´Â ¶óÀ̺귯¸® µð·ºÅ丮 ³»ÀÇ ÀÓÀÇÀÇ ÆÄÀϵ鿡 ´ëÇÑ ¿äûÀ» º¸³¿À¸·Î½á ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÒ ¼ö ÀÖ´Ù. ¼¼¹ø° °áÇÔÀº »ç¿ëÀÚ°¡ Á¦°øÇÑ ÀԷ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ °ËÁõÀ¸·Î ÀÎÇÑ Cross-Site Scripting °áÇÔÀÌ´Ù. ¿ø°ÝÁö °ø°ÝÀÚ´Â ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡¼ SQL Äõ¸®¹®À» ½ÇÇàÇÏ´Â °ÍÀ¸·Î ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÒ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.hardened-php.net/advisory_072006.130.html http://secunia.com/advisories/22126 http://archives.neohapsis.com/archives/fulldisclosure/2006-10/0006.html http://www.securityfocus.com/archive/1/archive/1/447491/100/0/threaded
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Tobias Ratschiller, phpMyAdmin 2.9.0.1 ÀÌÀüÀÇ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
phpMyAdmin ´Ù¿î·Îµå À¥ ÆäÀÌÁöÀÎ http://www.phpmyadmin.net/home_page/downloads.php ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â phpMyAdminÀÇ °¡Àå ÃֽŠ¹öÀü(2.9.0.1 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2006-5116,CVE-2006-5117 (CVE) |
°ü·Ã URL |
20253 (SecurityFocus) |
°ü·Ã URL |
29329,29330,29301 (ISS) |
|