CVE-2018-8974, CVE-2018-9113
[º¸¾È´º½º ¹®°¡¿ë ±âÀÚ] ÇöÁö ½Ã°¢À¸·Î 4¿ù 25ÀÏ, ¿ì¸®³ª¶ó ½Ã°£À¸·Î´Â ´ë·« 25ÀÏ¿¡¼ 26ÀÏ·Î ³Ñ¾î¿À´Â ¹ã »çÀÌ¿¡ ¹Ì±¹ÀÇ National Vulnerability DatabaseÀ» ÅëÇØ ¹ßÇ¥µÈ Ãë¾àÁ¡µéÀÌ´Ù.
[À̹ÌÁö = iclickart]
1. CVE-2018-10422
HongCMS 3.0.0 ¹öÀü¿¡¼ ¹ß°ßµÈ Ãë¾àÁ¡À¸·Î post news ±â´ÉÀÇ content Çʵ忡 XSS °ø°ÝÀÌ °¡´ÉÇÏ´Ù.
2. CVE-2018-10423
MiniCMS 1.10 ¹öÀüÀÇ mc-admin/post.phpÀÇ Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ À¥ ·çÆ®ÀÇ µð·ºÅ丮 ¸ñ·ÏÀ» ÃëµæÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
3. CVE-2018-10424
MiniCMS 1.10 ¹öÀüÀÇ mc-admin/post-edit.phpÀÇ Ãë¾àÁ¡À¸·Î Á¶ÀÛµÈ id Çʵ带 ÅëÇØ ¿ÏÀü °æ·Î°¡ ³ëÃâµÉ ¼ö ÀÖ´Ù.
4. CVE-2018-8974
Centers for Disease Control and Prevention MicrobeTRACE 0.1.11 ¹öÀüÀÇ Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ Á¶ÀÛµÈ CSV ÆÄÀÏÀ» ÅëÇØ ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
5. CVE-2018-9113
Centers for Disease Control and Prevention MicrobeTRACE 0.1.12 ¹öÀüÀÇ Ãë¾àÁ¡À¸·Î ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ Á¶ÀÛµÈ CSV ÆÄÀÏÀ» ÅëÇØ ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ°Ô ÇØÁØ´Ù.
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>