Ãë¾àÁ¡ID |
21996 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç WordPress ÇÁ·Î±×·¥Àº ¹éµµ¾î ÆÄÀϵ鿡 ÀÇÇÑ ¿ø°Ý ¸í·É ½ÇÇà Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. WordPress ´Â MySQL µ¥ÀÌÅͺ£À̽º¸¦ »ç¿ëÇÏ´Â PHP ±â¹ÝÀÇ ÃâÆÇ(publication) ÇÁ·Î±×·¥À¸·Î¼, ¹«·á·Î »ç¿ë °¡´ÉÇÑ ÇÁ·Î±×·¥ÀÌ´Ù. WordPress ¹öÀü 2.1.1Àº wp-includes/feed.php ½ºÅ©¸³Æ®·ÎÀÇ ix Àμö¿¡ ÀÖ´Â eval ÁÖÀÔ Ãë¾àÁ¡°ú wp-includes/theme.php ½ºÅ©¸³Æ®·ÎÀÇ iz Àμö¿¡ ÀÖ´Â ½Å·ÚÇÒ ¼ö ¾ø´Â passthru È£ÃâÀ» ÅëÇØ, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ÀÓÀÇÀÇ ¸í·ÉµéÀ» ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© À¥ ¼¹öÀÇ ±ÇÇÑÀ» °¡Áö°í ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ PHP Äڵ峪 ȤÀº ¾ÇÀÇÀûÀÎ ½© ¸í·ÉµéÀ» ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. º¸°í¿¡ µû¸£¸é ÀÌ Ãë¾àÁ¡Àº º¥´õÀÇ ¼¹ö¿¡ ħÅõÇÑ °ø°ÝÀÚ¿¡ ÀÇÇØ ¾îÇø®ÄÉÀ̼ǿ¡ Ãß°¡µÇ¾îÁ³´Ù.
* Âü°í »çÀÌÆ®: http://wordpress.org/development/2007/03/upgrade-212/ http://ifsec.blogspot.com/2007/03/wordpress-code-compromised-to-enable.html http://www.securityfocus.com/archive/1/461794/30/0/threaded http://secunia.com/advisories/24374/ http://www.kb.cert.org/vuls/id/214480 http://www.kb.cert.org/vuls/id/641456
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Matthew Mullenweg, WordPress 2.1.1 ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
WordPress ´Ù¿î·Îµå À¥ »çÀÌÆ®ÀÎ http://wordpress.org/download/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â WordPressÀÇ °¡Àå ÃֽŠ¹öÀü(2.1.2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2007-1277 (CVE) |
°ü·Ã URL |
22797 (SecurityFocus) |
°ü·Ã URL |
32804,32807 (ISS) |
|