Title : GNUBoard "g4_path" Parameter Local File Inclusion Vulnerability
Release Date : 2009-01-16
¼¼ºÎ¼³¸í
==========
GNUBoard¿¡¼ °ø°ÝÀÚ°¡ ¹Î°¨ÇÑ Á¤º¸¸¦ ¾òÀ» ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ È®ÀεǾú´Ù. ÀÌ ¹®Á¦´Â "common.php" ½ºÅ©¸³Æ®¿¡¼
"g4_path" ÆĶó¸ÞÅ͸¦ ó¸®ÇÒ ¶§ ÀÔ·Â °ª °ËÁõ ¿¡·¯ ¶§¹®ÀÌ´Ù. ÀÌ°ÍÀº °ø°ÝÀÚ°¡ À¥ ¼¹öÀÇ ±ÇÇÑÀ¸·Î
·ÎÄà ÆÄÀÏÀ» Æ÷ÇÔÇϰųª ³»¿ëÀ» ³ëÃâ½Ãų ¼ö ÀÖ´Ù.
ÇØ°áÃ¥
==========
±×´©º¸µå º¸¾ÈÆÐÄ¡¸¦ Àû¿ëÇϽñ⠹ٶø´Ï´Ù. (Âü°íÆäÀÌÁö ÂüÁ¶)
¿µÇâ¹Þ´Â ¹öÀü
==========
GNUBoard version 4.31.03 and prior
Âü°íÆäÀÌÁö : http://sir.co.kr/bbs/board.php?bo_table=g4_pds&wr_id=4215