Ãë¾àÁ¡ID |
21371 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç À¥¼¹ö¿¡ ¼³Ä¡µÈ PostNuke ¿¡´Â News ¸ðµâ¿¡ ÀÖ´Â Cross-Site Scripting Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Francisco Burzi ¿¡ ÀÇÇØ °³¹ßµÈ PostNuke´Â MySQL µ¥ÀÌÅͺ£À̽º¸¦ »ç¿ëÇÏ´Â PHP ÄÁÅÙÆ® °ü¸® ½Ã½ºÅÛÀÌ´Ù. PostNuke 0.7.2.0°ú 0.7.2.1 ¹öÀüµé¿¡´Â News ¸ðµâÀÇ article.php ½ºÅ©¸³Æ®·Î º¸³»Áö´Â "sid" º¯¼ö¸¦ ÀûÀýÈ÷ ÇÊÅ͸µÇÏÁö ¸øÇÔÀ¸·Î ÀÎÇÑ Cross-Site Scripting Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. ÀÌ °ø°ÝÀ» ¼º°øÀûÀ¸·Î µµ¿ëÇϸé, ¿ø°ÝÁö °ø°ÝÀÚµéÀº ¼¼¼Ç ÄíŰ Á¤º¸¸¦ ÈÉÄ¡°Å³ª »ç¿ëÀÚµéÀÇ Áß¿äÇÑ °³ÀÎ Á¤º¸µéÀ» ¾×¼¼½ºÇÒ ¼ö ÀÖ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Francisco Burzi, PostNuke 0.7.2.0 Francisco Burzi, PostNuke 0.7.2.1 Windows Any version Unix Any version Linux Any version |
ÇØ°áÃ¥ |
PostNuke´Â ´õ ÀÌ»ó Áö¿øµÇÁö ¾Ê´Â´Ù. ´Ù¸¥ ¼Ö·ç¼ÇÀ¸·Î ´ëüÇÒ °ÍÀ» ±Ç°íÇÑ´Ù. |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
5809 (SecurityFocus) |
°ü·Ã URL |
10239 (ISS) |
|