Ãë¾àÁ¡ID |
21396 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç WebCalendarÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ÀÌ ÇÁ·Î±×·¥¿¡´Â ´ÙÁßÀÇ ¿ø°Ý Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù. WebCalendar´Â ´ÜÀÏ »ç¿ëÀÚ³ª ÀÎÅͶó³Ý »ç¿ëÀÚµéÀÇ ±×·ìÀ» À§ÇÑ ´Þ·ÂÀ» °ü¸®ÇÏ´Â µ¥ »ç¿ëµÇ´Â ±×·¡ÇÇÄÃÇÑ PHP ¾îÇø®ÄÉÀ̼ÇÀÌ´Ù. WebCalendar 0.9.44 ÀÌÇÏÀÇ ¹öÀüµéÀº ¸¹Àº ½ºÅ©¸³Æ®µé¿¡¼ ´ÙÁßÀÇ Cross-Site Scripting Ãë¾àÁ¡µé, HTTP ÀÀ´ä ºÐÇÒ Ãë¾àÁ¡, SQL »ðÀÔ Ãë¾àÁ¡, ±×¸®°í µÎ °³ÀÇ ÀÎÁõ ¿ìȸ Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â Àß Á¶ÀÛµÈ URL ¿äûÀ» º¸³» ÇÁ·Î±×·¥¿¡ ´ëÇÑ ºñÀΰ¡µÈ ¾×¼¼½º¸¦ ÇÒ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ¸¸¾à ÀÌ Á¡°ËÇ׸ñÀÌ ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç WebCalendar ÇÁ·Î±×·¥ÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/archive/1/380821
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Craig Knudsen, WebCalendar 0.9.44 ÀÌÇÏÀÇ ¹öÀüµé Linux Any version Microsoft Windows Any version Unix Any version |
ÇØ°áÃ¥ |
´ÙÀ½ SourceForge À¥ »çÀÌÆ®¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â WebCalendarÀÇ °¡Àå ÃÖ½ÅÀÇ CVS ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://sourceforge.net/projects/webcalendar/ |
°ü·Ã URL |
CVE-2004-1506,CVE-2004-1507,CVE-2004-1508,CVE-2004-1509,CVE-2004-1510 (CVE) |
°ü·Ã URL |
11651 (SecurityFocus) |
°ü·Ã URL |
18026,18027,18028,18029,18030 (ISS) |
|