English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21362
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç ¿ø°ÝÁö À¥ ¼­¹ö »ó¿¡ ¼³Ä¡µÈ w-Agora ÇÁ·Î±×·¥ÀÇ ¹öÀü¿¡ µû¸£¸é, ÇÁ·Î±×·¥¿¡´Â ´Ù¼öÀÇ Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù.
w-Agora ´Â Microsoft Windows, Linux ¿Í Linux °è¿­ÀÇ ¿î¿µÃ¼Á¦¿¡¼­ µ¿ÀÛÇÏ´Â PHP ±â¹ÝÀÇ À¥ Æ÷·³°ú ÃâÆÇ(publishing) ÇÁ·Î±×·¥À¸·Î¼­, ¹«·á·Î »ç¿ë °¡´ÉÇÏ´Ù. w-Agora 4.1.6a ¹öÀü¿¡´Â ´ÙÀ½°ú °°Àº ´Ù¼öÀÇ Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù.

- GET/POST Cross-Site Scripting Ãë¾àÁ¡: ¿ø°ÝÁö °ø°ÝÀÚµéÀº Àß Á¶ÀÛµÈ subscribe_thread.php ½ºÅ©¸³Æ® ¿äûÀ» Àü´ÞÇÏ´Â ¹æ¹ýÀ¸·Î, ¼­¹ö·Î ÇÏ¿©±Ý ºÐ¸®µÈ ÀÀ´äÀ» ¹ÝȯÇϵµ·Ï ¸¸µé ¼ö ÀÖ´Ù. ÀÌ´Â cache poison °ø°Ý, cross-site scripting À» ºñ·ÔÇÏ¿© Áß¿äÇÑ Á¤º¸¸¦ ȹµæÇÏ´Â µî º¸´Ù Áö´ÉÈ­µÈ °ø°ÝÀ» ¼öÇàÇÒ ÀÖ´Ù.
- 'redir_url.php' SQL Injection Ãë¾àÁ¡: ¿ø°ÝÁö °ø°ÝÀÚµéÀº SQL ¸í·ÉµéÀ» Æ÷ÇÔÇÏ´Â redir_url.php ½ºÅ©¸³Æ® ¿äûÀ» Àü´ÞÇÏ´Â ¹æ¹ýÀ¸·Î, ÈÄÀ§ µ¥ÀÌÅͺ£À̽º »óÀÇ µ¥ÀÌÅ͸¦ ¼öÁ¤, »èÁ¦ ¶Ç´Â Ãß°¡ÇÒ ¼ö ÀÖ´Ù.
- HTTP response splitting Ãë¾àÁ¡: ¿ø°ÝÁö °ø°ÝÀÚµéÀº Àß Á¶ÀÛµÈ ¾ÇÀÇÀûÀÎ URL(download_thread.php¿¡ ´ëÇÑ HTTP GET ¿äû ¶Ç´Â login.php ¶Ç´Â forgot_password.php¿¡ ´ëÇÑ HTTP POST ¿äû)À» »ý¼ºÇϰí À̸¦ »ç¿ëÀÚ°¡ Ŭ¸¯Çϵµ·Ï À¯µµÇÑ´Ù. ÀÏ´Ü URL ¸µÅ©°¡ Ŭ¸¯µÇ¸é, »ðÀÔµÈ ÄÚµåµéÀº ´ë»ó »ç¿ëÀÚÀÇ À¥ ºê¶ó¿ìÀú¸¦ ÅëÇØ ½ÇÇàµÉ ¼ö ÀÖ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© »ç¿ëÀÚÀÇ ÄíŰ(cookie) ±â¹Ý ÀÎÁõ ½Å¿ë Á¤º¸µéÀ» ÈÉÄ¥ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ¿ø°ÝÁö À¥ ¼­¹ö »ó¿¡ ¼³Ä¡µÈ w-Agora ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://securitytracker.com/alerts/2004/Sep/1011463.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
W-Agora W-Agora 4.1.6 a
Microsoft Windows Any version
Unix Any version
Linux Any version
ÇØ°áÃ¥ ´ÙÀ½ w-Agora À¥ »çÀÌÆ®·ÎºÎÅÍ ´ÙÀ½ ½ºÅ©¸³Æ®µéÀÇ °¡Àå ÃÖ½ÅÀÇ CVS ¹öÀüÀ» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.w-agora.net/en/download.php
- subscribe_thread.php3 (1.17 ¶Ç´Â ±× ÀÌÈÄ)
- forgot_password.php3 (1.17 ¶Ç´Â ±× ÀÌÈÄ)
- include/auth.php (1.45 ¶Ç´Â ±× ÀÌÈÄ)
- list.php3 (1.53 ¶Ç´Â ±× ÀÌÈÄ)
°ü·Ã URL CVE-2004-1562,CVE-2004-1563,CVE-2004-1564 (CVE)
°ü·Ã URL 11283 (SecurityFocus)
°ü·Ã URL 17553,17557,17558 (ISS)