Ãë¾àÁ¡ID |
21349 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç À¥ ¼¹ö¿¡ ¼³Ä¡µÇ¾î ÀÖ´Â phpGroupWare ¹öÀü¿¡ µû¸£¸é, phpGroupWare¿¡´Â ´Ù¼öÀÇ Cross-Site Scripting Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù. Joseph EngoÀÇ phpGroupWare ´Â ÀüÀÚ¿ìÆí, ͏°´õ, To-Do ¸ñ·Ï°ú °°Àº ±â´ÉÀ» Æ÷ÇÔÇÏ´Â PHP ·Î Á¦ÀÛµÈ À¥ ±â¹ÝÀÇ ±×·ì¿þ¾î ½Ã½ºÅÛÀÌ´Ù. phpGroupWare 0.9.14.005 ÀÌÀüÀÇ ÀϺΠ¹öÀü¿¡´Â PHPGroupWare ¸ðµâµé¿¡ ÀÇÇØ »ç¿ëµÇ´Â Æû ÇÊµå »ó¿¡¼ ºÎÀûÀýÇÑ ÇÊÅ͸µÀ¸·Î ÀÎÇÏ¿© ´Ù¼öÀÇ Cross-Site Scripting Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº ¾ÇÀÇÀûÀÎ ½ºÅ©¸³Æ® Äڵ带 Æ÷ÇÔÇØ¼ Àß Á¶ÀÛµÈ URL ¸µÅ©¸¦ »ý¼ºÇÏ°í ´ë»ó »ç¿ëÀÚ°¡ À̸¦ Ŭ¸¯Çϵµ·Ï À¯µµÇÑ´Ù. ÀÏ´Ü URL ¸µÅ©°¡ Ŭ¸¯µÇ¸é, »ðÀÔµÈ ÄÚµåµéÀº ´ë»ó »ç¿ëÀÚÀÇ À¥ ºê¶ó¿ìÀú¸¦ ÅëÇØ ½ÇÇàµÉ ¼ö ÀÖ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© »ç¿ëÀÚÀÇ ÄíŰ(cookie) ±â¹Ý ÀÎÁõ ½Å¿ë Á¤º¸µéÀ» ÈÉÄ¥ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç phpGroupWare ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/bugtraq/2003-07/0022.html http://www.osvdb.org/2243
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: phpGroupWare 0.9.14.003 phpGroupWare 0.9.13 phpGroupWare 0.9.12 Conectiva Linux 7.0, 8.0, 9.0 Debian Linux 3.0 Mandrake Linux 8.2, 9.0, 9.1, Corporate Server 2.1 Linux Any version Windows Any version Unix Any version |
ÇØ°áÃ¥ |
phpGroupWare ´Ù¿î·Îµå »çÀÌÆ®ÀÎ http://prdownloads.sourceforge.net/phpgroupware/ ¿¡¼ phpGroupWareÀÇ °¡Àå ÃֽйöÀü(0.9.14.005 ¶Ç´Â ±× ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
Mandrake LinuxÀÇ °æ¿ì, MandrakeSoft º¸¾È ±Ç°í¹® MDKSA-2003:077, http://www.mandriva.com/en/support/security/advisories/ ¿¡¼ MDKSA-2003:077¸¦ Âü°íÇÏ¿©phpGroupWareÀÇ °¡Àå ÃֽйöÀüÀÇ ÆÐŰÁö¸¦ ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
Debian GNU/Linux 3.0 (woody)ÀÇ °æ¿ì, Debian º¸¾È ±Ç°í¹® DSA-365-1, http://www.debian.org/security/2003/dsa-365 ¿¡¼ phpGroupWareÀÇ °¡Àå ÃֽйöÀü(0.9.14-0.RC3.2.woody2 ¶Ç´Â ±× ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
´Ù¸¥ ¹èÆ÷ÆÇÀÇ °æ¿ì, ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¿¡ ´ëÇØ¼´Â ÇØ´ç Á¦Ç° Á¦Á¶»ç¿¡ ¹®ÀÇÇÑ´Ù. |
°ü·Ã URL |
CVE-2003-0504 (CVE) |
°ü·Ã URL |
8088 (SecurityFocus) |
°ü·Ã URL |
12497 (ISS) |
|