CVE-2018-9108, CVE-2018-9109
[º¸¾È´º½º ¹®°¡¿ë ±âÀÚ] ÇöÁö ½Ã°¢À¸·Î 3¿ù 27ÀÏ, ¿ì¸®³ª¶ó ½Ã°£À¸·Î´Â ´ë·« 27ÀÏ¿¡¼ 28ÀÏ·Î ³Ñ¾î¿À´Â ¹ã »çÀÌ¿¡ ¹Ì±¹ÀÇ National Vulnerability DatabaseÀ» ÅëÇØ ¹ßÇ¥µÈ Ãë¾àÁ¡µéÀÌ´Ù.
[À̹ÌÁö = iclickart]
1. CVE-2018-8823
Responsive Mega Menu Pro ¸ðµâ 1.0.32 ¹öÀüÀÇ modules/bamegamenu/ajax_phpcode.php¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚµéÀÌ ÀÓÀÇÀÇ PHP Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
2. CVE-2018-9106
Acyba AcySMS È®Àå ÇÁ·Î±×·¥ 3.5.1 ÀÌÀü ¹öÀüÀÇ CSV Injection Ãë¾àÁ¡À¸·Î CSV ¿¢½ºÆ÷Æ® ½Ã ¿À·ù°¡ ¹ß»ýÇÑ´Ù.
3. CVE-2018-9107
Acyba AcyMailing È®Àå ÇÁ·Î±×·¥ 5.9.6 ÀÌÀü ¹öÀüÀÇ CSV Injection Ãë¾àÁ¡À¸·Î CSV ¿¢½ºÆ÷Æ® ½Ã ¿À·ù°¡ ¹ß»ýÇÑ´Ù.
4. CVE-2018-9108
QuickAppsCMS 2.0.0-beta2 ¹öÀüÀÇ /admin/user/manage/addÀÇ CSRF Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áö°í °èÁ¤À» »ý¼ºÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
5. CVE-2018-9109
Studio 42 elFinder 2.1.36 ÀÌÀü ¹öÀüÀÇ elFinder.class.phpÀÇ zipdl() ÇÔ¼öÀÇ µð·ºÅ丮 Æ®¶ó¹ö¼³ Ãë¾àÁ¡À¸·Î °ø°ÝÀÚ°¡ ÆÄÀÏÀ» »èÁ¦ÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>