ํƒœ๊ทธ ๋ณด๊ด€๋ฌผ: supee-7405

supee-7405

๋ณด์•ˆ ํŒจ์น˜ SUPEE-7405-๊ฐ€๋Šฅํ•œ ๋ฌธ์ œ? https://magento.com/security/patches/supee-7405 ๋งˆ์ง€๋ง‰ ํŒจ์น˜์—

ํŒจ์น˜ ์ผ์ด ๋˜ ๋‚จ์•˜์Šต๋‹ˆ๋‹ค. Magento 1.x ์šฉ SUPEE-7405๊ฐ€ ๋‚˜์˜ค๊ณ  ์ˆ˜์ • ์‚ฌํ•ญ ๋ชฉ๋ก์ด ๋„ˆ๋ฌด ๊น๋‹ˆ๋‹ค. https://magento.com/security/patches/supee-7405

๋งˆ์ง€๋ง‰ ํŒจ์น˜์— ๋Œ€ํ•œ ๊ฒฝํ—˜์ด ์žˆ์œผ๋ฉด ํŒจ์น˜๋ฅผ ์ ์šฉ ํ•  ๋•Œ ๋ฐœ์ƒํ•  ์ˆ˜์žˆ๋Š” ๋ฌธ์ œ์ ๊ณผ ๊ณ ๋ คํ•ด์•ผ ํ•  ์‚ฌํ•ญ์ด ๋ฌด์—‡์ธ์ง€ ๋‹ค์‹œ ๋ฌป์Šต๋‹ˆ๋‹ค.

๋งŽ์€ XSS ๋ฌธ์ œ๊ฐ€ ๋‹ค์‹œ ์ˆ˜์ •๋˜์—ˆ์œผ๋ฏ€๋กœ ์‚ฌ์šฉ์ž ์ง€์ • ํ…Œ๋งˆ๋ฅผ ์ˆ˜๋™์œผ๋กœ ํŒจ์น˜ ํ•  ๊ฒƒ์œผ๋กœ ์˜ˆ์ƒ๋ฉ๋‹ˆ๋‹ค. ๋‹ค๋ฅธ ๊ฑฐ์žˆ์–ด? ์ด์ „ ๋ฒ„์ „๊ณผ ํ˜ธํ™˜๋˜์ง€ ์•Š๋Š” ๋ณ€๊ฒฝ์ด ์žˆ์Šต๋‹ˆ๊นŒ?



๋‹ต๋ณ€

2016 ๋…„ 2 ์›” 23 ์ผ ์—…๋ฐ์ดํŠธ : ํŒจ์น˜๊ฐ€ V1.1์œผ๋กœ ์—…๋ฐ์ดํŠธ๋˜์–ด์ด ๊ฒŒ์‹œ๋ฌผ์— ๋‚˜์—ด๋œ ์—ฌ๋Ÿฌ ๊ฐ€์ง€ ์ค‘์š”ํ•œ ๋ฌธ์ œ๊ฐ€ ํ•ด๊ฒฐ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๋ชฉ๋ก์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

  • ์นดํŠธ ๋ณ‘ํ•ฉ ํŒจ์น˜ (SUPEE-7978) : ๋™์ผํ•œ ์•„์ดํ…œ์„ ๊ฐ€์ง„ ์นดํŠธ๊ฐ€ ์˜ฌ๋ฐ”๋ฅด๊ฒŒ ๋ณ‘ํ•ฉ๋ฉ๋‹ˆ๋‹ค. ์ด์ „์—๋Š” ํ•œ ํ’ˆ๋ชฉ์ด์žˆ๋Š” ์นดํŠธ๊ฐ€ ๋™์ผํ•œ ํ’ˆ๋ชฉ์ด ํฌํ•จ ๋œ ๋‹ค๋ฅธ ์นดํŠธ์™€ ๋ณ‘ํ•ฉ ๋  ๋•Œ Magento๊ฐ€ ์žฅ๋ฐ”๊ตฌ๋‹ˆ ํ•ฉ๊ณ„๋ฅผ ์˜ฌ๋ฐ”๋ฅด๊ฒŒ ๋ณ‘ํ•ฉํ•˜์ง€ ์•Š์•˜์Šต๋‹ˆ๋‹ค. ์žฅ๋ฐ”๊ตฌ๋‹ˆ์—๋Š” ์ด์ œ ํ•˜๋‚˜์˜ ํ•ญ๋ชฉ ๋งŒ ํฌํ•จ๋˜๋ฉฐ ์ด๊ณ„๋Š” ์ •ํ™•ํ•ฉ๋‹ˆ๋‹ค.
  • SOAP API ํŒจ์น˜ (SUPEE-7822) : Magento SOAP API๊ฐ€ ์ด์ œ ์˜ˆ์ƒ๋Œ€๋กœ ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค. ์ด์ „์—๋Š” SUPEE-7405 v1.0 ํŒจ์น˜๋ฅผ ์„ค์น˜ ํ•œ ํ›„ API ์š”์ฒญ์œผ๋กœ ์ธํ•ด 500 ์˜ค๋ฅ˜๊ฐ€ ๋ฐœ์ƒํ–ˆ์œผ๋ฉฐ Magento๋Š” ์˜ˆ์™ธ๋ฅผ ๊ธฐ๋กํ–ˆ์Šต๋‹ˆ๋‹ค.
  • PHP 5.3 ํ˜ธํ™˜์„ฑ (SUPEE-7882) : ํŒจ์น˜๋Š”์ด ๋ฒ„์ „์„ ์ง€์›ํ•˜๊ณ ์žˆ๋Š” ์ด์ „ ๋ฒ„์ „์˜ Magento์˜ PHP 5.3๊ณผ ํ˜ธํ™˜๋˜์ง€ ์•Š์•˜์Šต๋‹ˆ๋‹ค. ์ด ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ•œ ํŒ๋งค์ž๋Š” ๊ด€๋ฆฌ์ž์—์„œ ํŒ๋งค ์ •๋ณด๋ฅผ ๋ณผ ์ˆ˜ ์—†์—ˆ์Šต๋‹ˆ๋‹ค.
  • ํŒŒ์ผ ์—…๋กœ๋“œ ๊ถŒํ•œ : ์›๋ณธ SUPEE-7405 ํŒจ์น˜์— ์˜ํ•ด ๋„์ž… ๋œ ๋” ์—„๊ฒฉํ•œ ๊ถŒํ•œ์œผ๋กœ ์ธํ•ด ํ˜ธ์ŠคํŒ… ์ œ๊ณต ์—…์ฒด ๊ตฌ์„ฑ์— ๋”ฐ๋ผ ๋งŽ์€ ํŒ๋งค์ž๊ฐ€ ์—…๋กœ๋“œ ํ•œ ์ œํ’ˆ ์ด๋ฏธ์ง€๋ฅผ ๋ณผ ์ˆ˜ ์—†์—ˆ๊ธฐ ๋•Œ๋ฌธ์— ํŒจ์น˜๋Š” ๋œ ์ œํ•œ์ ์ธ ํŒŒ์ผ ๊ถŒํ•œ (ํŒŒ์ผ์˜ ๊ฒฝ์šฐ 0666, ๋””๋ ‰ํ† ๋ฆฌ์˜ ๊ฒฝ์šฐ 0777)์„ ๋ณต์›ํ•ฉ๋‹ˆ๋‹ค. .

ํŒจ์น˜๋ฅผ ํŒŒ๊ณ  ๋“ค๊ณ  ๋‚˜๋ฉด ๋‚ด๊ฐ€ ์ฐพ์€ ๊ด€๋ จ / ํฅ๋ฏธ๋กœ์šด ๊ฒƒ๋“ค์ด ์žˆ์Šต๋‹ˆ๋‹ค (NB :์ด ๋ชฉ๋ก์€ CE 1.9.2.0-1.9.2.2์— ๋Œ€ํ•œ ํŒจ์น˜๋ฅผ ๋ถ„์„ํ•˜์—ฌ ๋งŒ๋“ค์–ด์กŒ์œผ๋ฉฐ, ์ด์ „ ๋ฒ„์ „์˜ Magento์— ์˜ํ–ฅ์„ ๋ฏธ์น˜๋Š” ํŒจ์น˜๊ฐ€ ๋”์žˆ์„ ๊ฒƒ์ž…๋‹ˆ๋‹ค) :

  • (ํŒจ์น˜ V1.1์—์„œ ์ˆ˜์ •) ์ด ํŒจ์น˜ []๋Œ€์‹ ์— array()๋ฅผ ์‚ฌ์šฉ ํ•˜๋ฉด PHP <5.4์™€ ํ˜ธํ™˜๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค (์•„๋ž˜ ์•Œ๋ ค์ง„ ๋ฌธ์ œ ์ฐธ์กฐ).
  • ์–ธ๊ธ‰ ํ•œ ๋ฐ”์™€ ๊ฐ™์ด ๋Œ€๋ถ€๋ถ„์˜ ๋ณ€๊ฒฝ ์‚ฌํ•ญ์€ XSS ๋ฌธ์ œ์™€ ๊ด€๋ จํ•˜์—ฌ HTML ์ด์Šค์ผ€์ดํ”„ ๋ฐ ๋ฐ์ดํ„ฐ ์‚ญ์ œ ์ž…๋‹ˆ๋‹ค.
  • ๊ด€๋ฆฌ์ž ๋กœ๊ทธ์ธ ์— ์–‘์‹ ํ‚ค ์œ ํšจ์„ฑ ๊ฒ€์‚ฌ ๊ฐ€ ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค .Mage_Admin_Model_Observer
  • ํผ ํ‚ค ์œ ํšจ์„ฑ ๊ฒ€์‚ฌ ๋ฐ›๋Š” ์‚ฌ๋žŒ์ด ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค ๊ด€๋ฆฌ์ž๊ฐ€ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์žŠ์–ด ๋ฒ„๋ ธ ์—Mage_Adminhtml_IndexController
  • ์–‘์‹ ํ‚ค ์œ ํšจ์„ฑ ๊ฒ€์‚ฌ ๊ฐ€ ๊ด€๋ฆฌ์ž ์žฌ์„ค์ • ๋น„๋ฐ€๋ฒˆํ˜ธ ์— ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค .Mage_Adminhtml_IndexController
  • ์–‘์‹ ํ‚ค ์œ ํšจ์„ฑ ๊ฒ€์‚ฌ ๊ฐ€ ํ”„๋ก ํŠธ ์—”๋“œ ์นดํŠธ ์‚ญ์ œ ์กฐ์น˜ ์— ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค . ํผ ํ‚ค์— ์ถ”๊ฐ€ getDeleteUrl์˜ Mage_Checkout_Block_Cart_Item_Renderer์ƒ๊ธฐ ๊ฒ€์ฆ์—์„œ deleteAction์˜ Mage_Checkout_CartController.
  • ์ด๋ฒคํŠธ๋Š” ์ด์ œ ๋ชจ๋“  ์†Œ๋ฌธ์ž๋กœ ์ „๋‹ฌ๋ฉ๋‹ˆ๋‹ค (์˜ํ–ฅ์„๋ฐ›๋Š” ๋ชจ๋“  ๊ตฌ์„ฑ ํŒŒ์ผ์ด ์ˆ˜์ • controller_action_postdispatch_checkout_onepage_saveOrder๋จ controller_action_postdispatch_checkout_onepage_saveorder). ์ด๊ฒƒ์€ ๋กœ์ปฌ ์˜ต์ €๋ฒ„ ๊ตฌ์„ฑ์— ์˜ํ–ฅ์„ ๋ฏธ์น˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค . ์ž์„ธํ•œ ๋‚ด์šฉ์€ ์—ฌ๊ธฐ : https://twitter.com/foomanNZ/status/689924329065164800
  • ์—…๋กœ๋“œ ๋œ ํŒŒ์ผ์ด ์ด๋ฏธ์ง€์ธ์ง€ ํ™•์ธ ํ•˜๋Š” ์ƒˆ๋กœ์šด ์œ ํšจ์„ฑ ๊ฒ€์‚ฌ๊ธฐ ๊ฐ€ ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค.Mage_Core_Model_File_Validator_Image
  • ์ƒˆ๋กœ์šด ๊ฐ€์ ธ ์˜ค๊ธฐ / ๋‚ด๋ณด๋‚ด๊ธฐ ์„น์…˜์ด ๋‚˜ํƒ€๋‚ฉ๋‹ˆ๋‹ค :System => Configuration =>Advanced > System => Escape CSV Fields
  • ์ƒˆ๋กœ์šด ์ด๋ฒคํŠธ ํŒŒ๊ฒฌ :admin_user_validate ๋ฏธ๋งŒMage_Admin_Model_User
  • SVG๋Š” ๋” ์ด์ƒ ์œ ํšจํ•œ ํŒŒ๋น„์ฝ˜ ํ™•์žฅ์ด ์•„๋‹™๋‹ˆ๋‹ค
  • Authorizenet์„ ์‚ฌ์šฉํ•˜๋Š” ์‚ฌ๋žŒ๋“ค์—๊ฒŒ๋Š” (๋ช‡ ๊ฐ€์ง€) ๋ณ€๊ฒฝ ์‚ฌํ•ญ์ด ์žˆ์ง€๋งŒ ์‹œ์Šคํ…œ์— ์–ด๋–ค ์˜ํ–ฅ์„ ๋ฏธ์น˜๋Š”์ง€ ํ™•์‹คํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. Mage_Authorizenet_Helper_Admin์„ฑ๊ณต ์ฃผ๋ฌธ URL์„ ์–ป๋Š” ๋ฐ ์‚ฌ์šฉ๋˜๋Š” ์ƒˆ๋กœ์šด ๊ด€๋ฆฌ์ž ๋„์šฐ๋ฏธ ( )๊ฐ€ ๋ณ€๊ฒฝ๋˜์—ˆ์Šต๋‹ˆ๋‹ค .
  • ์ƒˆ๋กœ์šด ์  ๋“œ ์ˆ˜์—… :Zend_Xml_Security . ๊ทธ ๋ชฉ์ ์€ ์ž ์žฌ์  ์ธ XXE ๋ฐ XEE ๊ณต๊ฒฉ์— ๋Œ€ํ•ด XML ๋ฌธ์ž์—ด์„ ์Šค์บ”ํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ๋‹ค๋ฅธ ์ˆ˜์ • ๋œ ํŒŒ์ผ์—์„œ ๊ทธ๊ฒƒ์— ๋Œ€ํ•œ ์ฐธ์กฐ๋ฅผ ์ฐพ์ง€ ๋ชปํ–ˆ์Šต๋‹ˆ๋‹ค.
  • ๊ด€๋ฆฌ์ž ํŒจ๋„์„ ํ†ตํ•ด ์—…๋กœ๋“œ ๋œ ํŒŒ์ผ (์˜ˆ : ์ œํ’ˆ ์ด๋ฏธ์ง€ ์—…๋กœ๋“œ) ์€ ๊ธฐ๋ณธ์ ์œผ๋กœ ์„ธ๊ณ„์—์„œ ์ฝ์„ ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค (์ด์ „ : 777 / ์ดํ›„ : 640).
  • ๋””๋ ‰ํ† ๋ฆฌ๋Š” ์›”๋“œ ์‹คํ–‰ ํŒŒ์ผ์ด ์•„๋‹™๋‹ˆ๋‹ค (755 ์ด์ „ / ์ดํ›„ : 750). ์›น ์„œ๋ฒ„๊ฐ€ PHP์™€ ๋‹ค๋ฅธ ์‚ฌ์šฉ์ž๋กœ ์‹คํ–‰๋˜๋Š” ๊ฒฝ์šฐ ์›น ์‚ฌ์ดํŠธ์— ์ด๋ฏธ์ง€๊ฐ€ ํ‘œ์‹œ๋˜์ง€ ์•Š๋Š” ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค (ํฌ๋ ˆ๋”ง : @Rob Mangiafico)
  • ์— ๊ด€ํ•œ ํ”„๋ก ํŠธ ์—”๋“œ ํ…œํ”Œ๋ฆฟ์„ ๋‹ค์Œ ๋งŒ๋“ค์–ด์ง„ ์œ ์ผํ•œ ์ˆ˜์ •ํ•˜๋Š” ํƒˆ์ถœ ๋ฐ์ดํ„ฐ ์‹œ์Šคํ…œ ์ฐจ๋‹จ๊ธฐ ์•„๋‹ˆ์ง€๋งŒ ์—ฌ์ „ํžˆ ์‚ฌ์šฉ์ž ์ง€์ • ํ…Œ๋งˆ์— ๊ตฌํ˜„ํ•˜๋Š” ๊ฒƒ์ด (๊ทธ๋ฆฌ๊ณ  ๊ทธ๋ ‡๊ฒŒ ๋งŽ์ดํ•˜์ง€ ์ž‘์—…์— ์˜ํ–ฅ์„ ๋‘ ํ”„๋ก ํŠธ ์—”๋“œ์˜ ํŒŒ์ผ์ด์žˆ๋‹ค๋Š”;))

ํŒจ์น˜ ํ›„ ์•Œ๋ ค์ง„ ๋ฌธ์ œ :

์ด ๋ชฉ๋ก์„ ๊ฐ€๋Šฅํ•œ ํ•œ ์ตœ์‹  ์ƒํƒœ๋กœ ์œ ์ง€ํ•˜๋„๋ก ๋…ธ๋ ฅํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค.

์ƒˆ๋กœ์šด ๋ฌธ์ œ / ์งˆ๋ฌธ์„ ์‹œ์ž‘ํ•˜๊ธฐ ์ „์— ๋ˆ„๋ฝ ๋œ ํŒจ์น˜๋กœ ์ธํ•ด ๋งŽ์€ ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ•˜๋Š” ๊ฒƒ์ฒ˜๋Ÿผ ๋ณด์ด๋Š” ์ด์ „ ํŒจ์น˜ ๋ฅผ ๋ชจ๋‘ ์ ์šฉ ํ–ˆ๋Š”์ง€ ํ™•์ธํ•˜์‹ญ์‹œ์˜ค .

๋˜ ๋‹ค๋ฅธ ๊ฒƒ์€ ์ฝ”์–ด ํŒŒ์ผ์„ ์ˆ˜์ • ํ•œ ๊ฒฝ์šฐ ํŒจ์น˜ ์ ์šฉ์— ์‹คํŒจ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋‹น์‹ ์ด ๋ฐœ์ƒํ•˜๋Š” ๊ฒฝ์šฐ Hunk # failed at: ํŠน์ • ํŒŒ์ผ์— ๋Œ€ํ•œ ์˜ค๋ฅ˜์™€ ์‚ฌ์šฉ์ž๊ฐ€ ์ด์ „์˜ ๋ชจ๋“  ํŒจ์น˜๋ฅผ ์ ์šฉํ–ˆ๋Š”์ง€ 100 % ๊ฒƒ, ๋ฏธ๋Ÿฌ๋ฅผ ์„ ํƒํ•˜์—ฌ ๋‹น์‹ ์€ ๋‹น์‹ ์˜ ์  ํ†  ๋ฒ„์ „์—์„œ ์›๋ณธ ํŒŒ์ผ์„ ํ™•์ธํ•˜์‹œ๊ธฐ ๋ฐ”๋ž๋‹ˆ๋‹ค https://github.com / OpenMage / magento- ๊ฑฐ์šธ /

์˜ํ–ฅ์„๋ฐ›๋Š” ํŒŒ์ผ ๋ชฉ๋ก

์ด ํŽ˜์ด์ง€์—์„œ ์ฐพ์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค : https://magento.stackexchange.com/a/98232/2380 (credits @MagenX)

EE ๋งŒ

  • ๋‹น์‹ ์€ ๋งˆ ์  ํ† ์— ์  ํ†  EE์˜ 1.14.2.x์—์„œ ์—…๋ฐ์ดํŠธ ํ•œ ๊ฒฝ์šฐ EE 1.14.2.3 ๋Œ€์‹ ์— ํŒจ์น˜๋ฅผ ์ ์šฉํ•˜๊ณ , ๋˜ํ•œ ์ง€์› ํŒจ์น˜ ์ ์šฉ SUPEE-5984๋ฅผ ํ•˜๊ธฐ ์ „์—, ๋‹น์‹ ์€ํ•ด์•ผ ๋‹ค์‹œ ๋‹ค์‹œ ์ ์šฉ ์ด๋˜๊ธฐ ๋•Œ๋ฌธ์— ๋ฆด๋ฆฌ์Šค์— ํฌํ•จ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค . => https://magento.stackexchange.com/a/98805/2380

ํŒจ์น˜ 7616์— ๊ด€ํ•˜์—ฌ :

  • ํŒจ์น˜๋ฅผ ์ ์šฉ ํ•˜๊ธฐ ์ „์— ํŒจ์น˜ 4291 ๋ฐ 6237์„ ์ ์šฉํ•ด์•ผํ•˜๋Š” ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค . ์ž์„ธํ•œ ์ •๋ณด๋Š” ์—ฌ๊ธฐ : 7616_EE 7405_EE ํŒจ์น˜ ์ ์šฉ์— ์‹คํŒจํ–ˆ์Šต๋‹ˆ๋‹ค
  • (ํŒจ์น˜ 5344๋Š” ์ ์šฉ๋˜์ง€ ์•Š์•˜์Šต๋‹ˆ๋‹ค) 7405๋ฅผ ์ ์šฉํ•˜๊ธฐ ์ „์— 7616์„ ์ ์šฉ ํ•  ๋•Œ ๋ฐœ์ƒํ•  ์ˆ˜์žˆ๋Š” ๋ฌธ์ œ : SUPEE 7405-Hunk # 2 Failed at 43

๋งˆ ์  ํ†  ํŒจ์น˜์— ๋Œ€ํ•œ ์ข‹์€ ์ž๋ฃŒ

๋‚ด๊ฐ€ ๋†“์นœ ๋ถ€๋ถ„์ด ์žˆ์œผ๋ฉด ์–ธ์ œ๋“ ์ง€ ์•Œ๋ ค์ฃผ์„ธ์š”.


๋‹ต๋ณ€

๋‚ด๊ฐ€ ์ฃผ๋ชฉ ํ•œ ํ•œ ๊ฐ€์ง€ ๋ฌธ์ œ๋Š” ์‚ฌ์ดํŠธ์—์„œ PHP 5.4 ๋ฏธ๋งŒ์˜ ๋ฒ„์ „์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ ํŒจ์น˜๊ฐ€ ํ˜ธํ™˜๋˜์ง€ ์•Š๋Š”๋‹ค๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค.

Mage_Adminhtml_Helper_Sales์ค„ ๋ฒˆํ˜ธ 124 ์ฃผ์œ„ ์˜ ํด๋ž˜์Šค ์—์„œ ์ฝ”๋“œ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

$links = [];

์ด๊ฒƒ์„ ๋‹ค์Œ๊ณผ ๊ฐ™์ด ํ™•์žฅํ•ด์•ผํ–ˆ์Šต๋‹ˆ๋‹ค.

        // Patch not compatible with PHP version 5.3: overwrote Magento patch update

        $links = array();

๋‚ด๊ฐ€ ๊ฒช์€ ๋˜ ๋‹ค๋ฅธ ์˜ค๋ฅ˜๋Š” ๋‚ด๊ฐ€ ์„ค์ • ํ•œ ์ฟ ํ‚ค์™€ ๊ด€๋ จ๋œ ๊ฒƒ์œผ๋กœ ๋ณด์ž…๋‹ˆ๋‹ค. ์ฟ ํ‚ค๋ฅผ ์ง€์šฐ๋ฉด ๋ชจ๋“  ํŽ˜์ด์ง€๊ฐ€ ์ •์ƒ์ ์œผ๋กœ๋กœ๋“œ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

์˜ค๋ฅ˜ ์˜ˆ :

Notice: unserialize() [function.unserialize]: Error at offset 0 of 13 bytes  in `/var/www/website/app/code/core/Mage/Core/Helper/Cookie.php` on line 83

๋‹ค๋ฅธ ์‚ฌ๋žŒ ์ด์ด ๋ฌธ์ œ์— ๋ถ€๋”ช ์ณค๋Š”์ง€ ํ™•์‹คํ•˜์ง€ ์•Š์ง€๋งŒ ๋„์›€์ด๋˜๊ธฐ๋ฅผ ๋ฐ”๋ž๋‹ˆ๋‹ค.


๋‹ต๋ณ€

SUPEE-7405๋กœ Magento CE๋ฅผ ํŒจ์น˜ ํ•  ๋•Œ ๋ฐœ๊ฒฌ ํ•œ ๋ฌธ์ œ๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. ๋‹ค์Œ ์ค„์„ ๋Œ€์ฒดํ•ฉ๋‹ˆ๋‹ค.

chmod($destinationFile, 0777);

์™€:

chmod($destinationFile, 0640);

ํŒŒ์ผ์—์„œ lib/Varien/File/Uploader.php

์ด ํŒŒ์ผ ๊ถŒํ•œ์€ ์‹ค์ œ๋กœ 644 ์—ฌ์•ผํ•˜๋ฏ€๋กœ ๋ฐฑ์—”๋“œ์— ์ด๋ฏธ์ง€๊ฐ€ ํ‘œ์‹œ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. 640์œผ๋กœ ์„ค์ • ํ•œ ์ด์œ ๊ฐ€ ์žˆ์Šต๋‹ˆ๊นŒ?


๋‹ต๋ณ€

Magento 1.7.0.0 ์‹ ์ฒญ์‹œ ๋Œ“๊ธ€ ์‚ญ์ œ app/design/adminhtml/default/default/template/authorizenet/directpost/iframe.phtml

-/* @var $_helper Mage_Authorizenet_Helper_Data */

1.7.0.0- https: //raw.githubusercontent.com/OpenMage/magento-mirror/1.7.0.0/app/design/adminhtml/default/default/template/authorizenet/directpost/iframe.phtml

1.7.0.1๊นŒ์ง€ ์ถ”๊ฐ€๋˜์ง€ ์•Š์•˜์Šต๋‹ˆ๋‹ค https://raw.githubusercontent.com/OpenMage/magento-mirror/1.7.0.1/app/design/adminhtml/default/default/template/authorizenet/directpost/iframe.phtml


๋‹ต๋ณ€

์ด ํŒŒ์ผ๋“ค์ด ํŒจ์น˜๋˜๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์˜ํ–ฅ์„ ๋ณผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
template : ๊ด€๋ฆฌ ํ…œํ”Œ๋ฆฟ ๋Œ€๋ถ€๋ถ„ ํŒจ์น˜.

+++ app/design/frontend/base/default/template/rss/order/details.phtml
+++ app/design/frontend/base/default/template/catalog/product/view/options/type/file.phtml
+++ app/design/adminhtml/default/default/template/sales/order/view/info.phtml
+++ app/design/adminhtml/default/default/template/sales/order/totals/discount.phtml
+++ app/design/adminhtml/default/default/template/sales/items/renderer/default.phtml
+++ app/design/adminhtml/default/default/template/sales/items/column/name.phtml
+++ app/design/adminhtml/default/default/template/downloadable/sales/items/column/downloadable/name.phtml
+++ app/design/adminhtml/default/default/template/downloadable/sales/items/column/downloadable/invoice/name.phtml
+++ app/design/adminhtml/default/default/template/downloadable/sales/items/column/downloadable/creditmemo/name.phtml
+++ app/design/adminhtml/default/default/template/catalog/product/composite/fieldset/options/type/file.phtml
+++ app/design/adminhtml/default/default/template/bundle/sales/shipment/view/items/renderer.phtml
+++ app/design/adminhtml/default/default/template/bundle/sales/shipment/create/items/renderer.phtml
+++ app/design/adminhtml/default/default/template/bundle/sales/order/view/items/renderer.phtml
+++ app/design/adminhtml/default/default/template/bundle/sales/invoice/view/items/renderer.phtml
+++ app/design/adminhtml/default/default/template/bundle/sales/invoice/create/items/renderer.phtml
+++ app/design/adminhtml/default/default/template/bundle/sales/creditmemo/view/items/renderer.phtml
+++ app/design/adminhtml/default/default/template/bundle/sales/creditmemo/create/items/renderer.phtml
+++ app/design/adminhtml/default/default/template/authorizenet/directpost/iframe.phtml

์ฝ”์–ด / ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ :

+++ lib/Varien/Io/File.php
+++ lib/Varien/File/Uploader.php
+++ app/code/core/Zend/Xml/Security.php
+++ app/code/core/Mage/Sales/Model/Quote/Item.php
+++ app/code/core/Mage/Sales/Model/Quote/Address.php
+++ app/code/core/Mage/Sales/Helper/Guest.php
+++ app/code/core/Mage/Rss/Helper/Order.php
+++ app/code/core/Mage/Rss/Block/Catalog/Salesrule.php
+++ app/code/core/Mage/Review/controllers/ProductController.php
+++ app/code/core/Mage/Paypal/controllers/PayflowadvancedController.php
+++ app/code/core/Mage/Paypal/controllers/PayflowController.php
+++ app/code/core/Mage/Newsletter/Model/Queue.php
+++ app/code/core/Mage/Newsletter/Model/Observer.php
+++ app/code/core/Mage/ImportExport/Model/Import/Entity/Abstract.php
+++ app/code/core/Mage/ImportExport/Model/Export/Adapter/Csv.php
+++ app/code/core/Mage/ImportExport/Model/Export/Adapter/Abstract.php
+++ app/code/core/Mage/Downloadable/controllers/CustomerController.php
+++ app/code/core/Mage/Dataflow/Model/Convert/Parser/Csv.php
+++ app/code/core/Mage/Customer/controllers/AccountController.php
+++ app/code/core/Mage/Core/Model/Session.php
+++ app/code/core/Mage/Core/Model/Input/Filter/MaliciousCode.php
+++ app/code/core/Mage/Core/Model/File/Validator/Image.php
+++ app/code/core/Mage/Core/Model/Email/Template/Filter.php
+++ app/code/core/Mage/Core/Model/Email/Queue.php
+++ app/code/core/Mage/Core/Model/Config.php
+++ app/code/core/Mage/Core/Model/App.php
+++ app/code/core/Mage/Core/Helper/Data.php
+++ app/code/core/Mage/Checkout/controllers/OnepageController.php
+++ app/code/core/Mage/Checkout/controllers/CartController.php
+++ app/code/core/Mage/Checkout/Block/Cart/Item/Renderer.php
+++ app/code/core/Mage/CatalogInventory/Helper/Minsaleqty.php
+++ app/code/core/Mage/Catalog/Model/Resource/Product/Attribute/Backend/Image.php
+++ app/code/core/Mage/Catalog/Model/Category/Attribute/Backend/Image.php
+++ app/code/core/Mage/Catalog/Block/Product/View/Options/Type/Select.php
+++ app/code/core/Mage/Authorizenet/controllers/Adminhtml/Authorizenet/Directpost/PaymentController.php
+++ app/code/core/Mage/Authorizenet/Helper/Data.php
+++ app/code/core/Mage/Authorizenet/Helper/Admin.php
+++ app/code/core/Mage/Adminhtml/controllers/IndexController.php
+++ app/code/core/Mage/Adminhtml/Model/System/Config/Backend/Image/Favicon.php
+++ app/code/core/Mage/Adminhtml/Model/System/Config/Backend/Image.php
+++ app/code/core/Mage/Adminhtml/Model/System/Config/Backend/File.php
+++ app/code/core/Mage/Adminhtml/Helper/Sales.php
+++ app/code/core/Mage/Adminhtml/Helper/Catalog/Product/Edit/Action/Attribute.php
+++ app/code/core/Mage/Adminhtml/Block/Widget/Grid.php
+++ app/code/core/Mage/Adminhtml/Block/Sales/Order/View/Tab/History.php
+++ app/code/core/Mage/Admin/Model/User.php
+++ app/code/core/Mage/Admin/Model/Resource/User.php
+++ app/code/core/Mage/Admin/Model/Redirectpolicy.php
+++ app/code/core/Mage/Admin/Model/Observer.php

===================================================== =====================
ps
๋ชจ๋“  ๊ฒƒ์„ ํ•จ๊ป˜ ์œ ์ง€ํ•˜๊ธฐ ์œ„ํ•ด, ๋‹ค์ˆ˜์˜ ๋งˆ ์  ํ†  ์„ค์น˜๋กœ ๋งŽ์€ ์„œ๋ฒ„๋ฅผ ํŒจ์น˜ํ•˜๊ธฐ ์œ„ํ•ด โ€œ๋‘๋‡Œ์—†๋Š”โ€๋ฉ€ํ‹ฐ ํŒจ์น˜๋ฅผ ๋งŒ๋“ค์—ˆ์Šต๋‹ˆ๋‹ค.
๋ฉ€ํ‹ฐ ํŒจ์น˜ -7405.sh


๋‹ต๋ณ€

๊ธฐ๋ณธ ํ…Œ์ŠคํŠธ ๊ณ„ํš์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

  • ์ฟ ํฐ ์ ์šฉ
  • ๊ด€๋ฆฌ์ž ๋กœ๊ทธ์ธ
  • ๊ด€๋ฆฌ์ž๊ฐ€ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ๋ณ€๊ฒฝํ•˜๋„๋ก ๊ฐ•์ œ
  • CSV ๋‚ด๋ณด๋‚ด๊ธฐ
  • CSV ๊ฐ€์ ธ ์˜ค๊ธฐ
  • ๊ด€๋ฆฌ์ž ๋ฐ ๊ณ ๊ฐ์œผ๋กœ ๋น„๋ฐ€๋ฒˆํ˜ธ ์žฌ์„ค์ •
  • ๊ด€๋ฆฌ์ž์—์„œ ์ฃผ๋ฌธ ์ž‘์„ฑ
  • ํ”„๋ŸฐํŠธ ์—”๋“œ์—์„œ ๊ฒŒ์ŠคํŠธ๋กœ ์ƒ์„ฑ ๋ฐ ์ฃผ๋ฌธ
  • ํ”„๋ŸฐํŠธ ์—”๋“œ์—์„œ ๊ณ ๊ฐ์œผ๋กœ ์ƒ์„ฑ ๋ฐ ์ฃผ๋ฌธ
  • ์ œํ’ˆ์— ์ด๋ฏธ์ง€ ์ถ”๊ฐ€
  • ๋Œ€๋ณ€ โ€‹โ€‹๋ฉ”๋ชจ ์ž‘์„ฑ
  • ์†ก์žฅ ์ž‘์„ฑ

๋‹ต๋ณ€

Colin Mollenhour๊ฐ€ ์ตœ๊ทผ์— ๋ฐœ๊ฒฌํ•˜๊ณ  ์ˆ˜์ • ํ•œ ์„ธ์…˜ ์‚ญ์ œ ๋ฌธ์ œ์— ์œ ์˜ํ•˜์‹ญ์‹œ์˜ค .

https://gist.github.com/colinmollenhour/5066a3220881a9c0c2dd42fa1593cbff/revisions