English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21396
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç WebCalendarÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ÀÌ ÇÁ·Î±×·¥¿¡´Â ´ÙÁßÀÇ ¿ø°Ý Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù.
WebCalendar´Â ´ÜÀÏ »ç¿ëÀÚ³ª ÀÎÅͶó³Ý »ç¿ëÀÚµéÀÇ ±×·ìÀ» À§ÇÑ ´Þ·ÂÀ» °ü¸®ÇÏ´Â µ¥ »ç¿ëµÇ´Â ±×·¡ÇÇÄÃÇÑ PHP ¾îÇø®ÄÉÀ̼ÇÀÌ´Ù. WebCalendar 0.9.44 ÀÌÇÏÀÇ ¹öÀüµéÀº ¸¹Àº ½ºÅ©¸³Æ®µé¿¡¼­ ´ÙÁßÀÇ Cross-Site Scripting Ãë¾àÁ¡µé, HTTP ÀÀ´ä ºÐÇÒ Ãë¾àÁ¡, SQL »ðÀÔ Ãë¾àÁ¡, ±×¸®°í µÎ °³ÀÇ ÀÎÁõ ¿ìȸ Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â Àß Á¶ÀÛµÈ URL ¿äûÀ» º¸³» ÇÁ·Î±×·¥¿¡ ´ëÇÑ ºñÀΰ¡µÈ ¾×¼¼½º¸¦ ÇÒ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ¸¸¾à ÀÌ Á¡°ËÇ׸ñÀÌ ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç WebCalendar ÇÁ·Î±×·¥ÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/380821

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Craig Knudsen, WebCalendar 0.9.44 ÀÌÇÏÀÇ ¹öÀüµé
Linux Any version
Microsoft Windows Any version
Unix Any version
ÇØ°áÃ¥ ´ÙÀ½ SourceForge À¥ »çÀÌÆ®¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â WebCalendarÀÇ °¡Àå ÃÖ½ÅÀÇ CVS ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://sourceforge.net/projects/webcalendar/
°ü·Ã URL CVE-2004-1506,CVE-2004-1507,CVE-2004-1508,CVE-2004-1509,CVE-2004-1510 (CVE)
°ü·Ã URL 11651 (SecurityFocus)
°ü·Ã URL 18026,18027,18028,18029,18030 (ISS)