|
Ä¿ÇÇÇâÀÌ ³ª´Â *NIX
Ä¿ÇǴнº
½Ã½ºÅÛ/³×Æ®¿÷/º¸¾ÈÀ» ´Ù·ç´Â °÷
|
|
|
|
ÀÌÀü ÁÖÁ¦ º¸±â :: ´ÙÀ½ ÁÖÁ¦ º¸±â |
±Û¾´ÀÌ |
¸Þ½ÃÁö |
truefeel Ä«Æä °ü¸®ÀÚ
°¡ÀÔ: 2003³â 7¿ù 24ÀÏ ¿Ã¸° ±Û: 1277 À§Ä¡: ´ëÇѹα¹
|
¿Ã·ÁÁü: 2005.7.03 ÀÏ, 9:47 pm ÁÖÁ¦: phpBB¿¡ ¿ø°ÝÁö phpÄÚµå ½ÇÇàÇÏ´Â Ãë¾àÁ¡ ¹ß°ß |
|
|
phpBB¿¡ ½É°¢ÇÑ Ãë¾àÁ¡ÀÌ ¿ÃÇØ¸¸Çصµ ¿©·¯¹ø ¹ßÇ¥µÇ°í ÀÖ½À´Ï´Ù.
phpBB 2.0.15 ÀÌÀü ¹öÀüÀÇ viewtopic.php ¿¡¼ highlight ÆÄ¶ó¹ÌÅÍ »ç¿ëÇÒ ¶§ ¹®Á¦Àä,
Å×½ºÆ®ÇÑ °á°ú ÀϺιöÀü¿¡¼ ´ÙÀ½°ú °°Àº query·Î phpinfo() ÇÔ¼ö ½ÇÇàÀÌ °¡´ÉÇß½À´Ï´Ù.
ÄÚµå: |
viewtopic.php?t=1&&highlight='.phpinfo().'
|
* phpBB "highlight" PHP Code Execution Vulnerability
Àοë: |
Description:
Ron van Daal has reported a vulnerability in phpBB, which can be exploited by malicious people to compromise a vulnerable system.
Input passed to the "highlight" parameter in "viewtopic.php" is not properly sanitised before being used in a "preg_replace()" call with the "e" modifier. This can be exploited to inject arbitrary PHP code.
NOTE: This is related to an older vulnerability incorrectly fixed in version 2.0.11.
The vulnerability has been reported in version 2.0.15 and prior.
|
http://secunia.com/advisories/15845/
http://www.securityfocus.com/bid/14086/info
* phpBB 2.0.15 ÀÌÀü Ãë¾àÁ¡°ú 2.0.16 release
http://www.phpbb.com/phpBB/viewtopic.php?t=302011 |
|
À§·Î |
|
 |
|
|
»õ·Î¿î ÁÖÁ¦¸¦ ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù ´ä±ÛÀ» ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù ÁÖÁ¦¸¦ ¼öÁ¤ÇÒ ¼ö ¾ø½À´Ï´Ù ¿Ã¸° ±ÛÀ» »èÁ¦ÇÒ ¼ö ¾ø½À´Ï´Ù ÅõÇ¥¸¦ ÇÒ ¼ö ¾ø½À´Ï´Ù
|
Powered by phpBB © 2001, 2005 phpBB Group
|