English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21300
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç Moodle ¼ÒÇÁÆ®¿þ¾î´Â 'help.php' ½ºÅ©¸³Æ®¸¦ »ç¿ëÇÑ Cross-Site Scripting Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù.
MoodleÀº Microsoft Windows¿Í Unix ¹× Linux ±â¹ÝÀÇ Ç÷§Æûµé »ó¿¡¼­ µ¿ÀÛÇϵµ·Ï Á¦ÀÛµÈ PHP ±â¹ÝÀÇ ¿ÀÇ ¼Ò½º ÄÚ½º °ü¸® ½Ã½ºÅÛ(CMS:course management system)ÀÌ´Ù. Moodle 1.3 ÀÌÀüÀÇ ¹öÀüµéÀº ¿ø°ÝÁö °ø°ÝÀÚµéÀÌ ´ÙÀ½°ú °°ÀÌ 'help.php' ½ºÅ©¸³Æ®¿¡ HTML ¶Ç´Â ÀÚ¹Ù½ºÅ©¸³Æ®¸¦ »ðÀÔÇÏ¿© Àß Á¶ÀÛÇÑ URL ¸µÅ©¸¦ Àü´ÞÇÒ ¼ö ÀÖ´Ù:

http://[target.host]/help.php?text=%3Cscript%3Efoo%3C/script%3E

ÀÏ´Ü ÀÌ ¸µÅ©°¡ »ç¿ëÀÚ¿¡ ÀÇÇØ Ŭ¸¯µÇ¸é, »ðÀÔµÈ ÄÚµåµéÀÌ ÇØ´ç ¼­¹öÀÇ ±ÇÇÑÀ¸·Î »ç¿ëÀÚÀÇ À¥ ºê¶ó¿ìÀú »ó¿¡¼­ ½ÇÇàµÉ ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡µéÀ» µµ¿ëÇÏ¿©, ¿ø°ÝÁö °ø°ÝÀÚµéÀº ÄíŰ(cookie) ±â¹ÝÀÇ ÀÎÁõ ½Å¿ëÁ¤º¸¸¦ ÈÉÄ¡°Å³ª ±âŸ ´Ù¸¥ °ø°ÝÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2004-04/0357.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Moodle moodle 1.1.1
Moodle moodle 1.2
Moodle moodle 1.2.1
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ ´ÙÀ½ÀÇ Moodle ´Ù¿î·Îµå »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© °¡Àå ÃֽйöÀüÀÎ 1.3 ÀÌÈÄ ¹öÀüÀ¸·Î ¾÷±×·¹À̵åÇÏ¿©¾ß ÇÑ´Ù:
http://download.moodle.org/

Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î, Bartek Nowotarski°¡ Á¦¾ÈÇÑ ´ÙÀ½°ú °°Àº ÀÓ½ÃÀûÀÎ ÆÐÄ¡°¡ Á¸ÀçÇÑ´Ù. ±×·¯³ª, ÀÌ ÆÐÄ¡´Â Symantec ¶Ç´Â ±âŸ º¥´õµé¿¡ ÀÇÇØ È®ÀεÇÁö ¾Ê¾ÒÀ½À» ÁÖÀÇÇÏ¿©¾ß ÇÑ´Ù.
¹öÀü 1.2ÀÇ 'help.php' ½ºÅ©¸³Æ®ÀÇ 75¶óÀÎ »óÀÇ ÅØ½ºÆ® 'echo "$text";'¸¦ 'echo clean_text($text);'·Î ¼öÁ¤ÇÑ´Ù.
°ü·Ã URL CVE-2004-1978 (CVE)
°ü·Ã URL 10251 (SecurityFocus)
°ü·Ã URL 16023 (ISS)