English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21323
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥¼­¹ö¿¡ ¼³Ä¡µÈ PostNuke ¿¡´Â Reviews ¸ðµâ¿¡ ÀÖ´Â Cross-Site Scripting Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
Francisco Burzi ¿¡ ÀÇÇØ °³¹ßµÈ PostNuke´Â MySQL µ¥ÀÌÅͺ£À̽º¸¦ »ç¿ëÇÏ´Â PHP ÄÁÅÙÆ® °ü¸® ½Ã½ºÅÛÀÌ´Ù. PostNuke ¹öÀü 0.726-3 ±×¸®°í 0.75-RC3À» Æ÷ÇÔÇÑ ¿©·¯ ¹öÀüµé¿¡´Â 'Reviews' ½ºÅ©¸³Æ®ÀÇ 'title' Àμö¸¦ ÀûÀýÈ÷ ÇÊÅ͸µÇÏÁö ¸øÇÔÀ¸·Î ÀÎÇÑ Cross-Site Scripting Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. ÀÌ °ø°ÝÀ» ¼º°øÀûÀ¸·Î µµ¿ëÇϸé, ¿ø°ÝÁö °ø°ÝÀÚµéÀº ¼¼¼Ç ÄíŰ Á¤º¸¸¦ ÈÉÄ¡°Å³ª »ç¿ëÀÚµéÀÇ Áß¿äÇÑ °³ÀÎ Á¤º¸µéÀ» ¾×¼¼½ºÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://securitytracker.com/alerts/2004/Jul/1010733.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
PostNuke Development Team PostNuke 0.75-RC3
PostNuke Development Team PostNuke 0.726-3
Windows Any version
Unix Any version
Linux Any version
ÇØ°áÃ¥ 2014³â 6¿ù ÇöÀç PostNuke´Â ´õ ÀÌ»ó °³¹ßµÇÁö ¾Ê´Â´Ù. ´Ù¸¥ ¼Ö·ç¼ÇÀ¸·Î º¯°æÇØ¾ß ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL 10802 (SecurityFocus)
°ü·Ã URL (ISS)