English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21444
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®´Â ´ÙÁßÀÇ Ãë¾àÁ¡µéÀ» °¡Áø MySQL EventumÀÌ °¡µ¿ ÁßÀÎ °ÍÀ¸·Î ³ªÅ¸³­´Ù.
EventumÀº MySQL µ¥ÀÌÅͺ£À̽º¸¦ »ç¿ëÇÏ´Â PHP·Î Á¦ÀÛµÈ ´Ù±â´ÉÀÇ ¹®Á¦ ÃßÀû ½Ã½ºÅÛÀÌ´Ù. Eventum 1.3.1 ÀÌÇÏÀÇ ¹öÀüµéÀº ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇϸç, ÀÌ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ Cross-Site Scripting°ú ½ºÅ©¸³Æ® ÁÖÀÔ °ø°Ýµé ±×¸®°í º¸¾È Á¦ÇÑÀÇ ¿ìȸ¸¦ ¼öÇàÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.

1. "index.php" ±×¸®°í "forgot_password.php"¿¡ ÀÖ´Â "email" Àμö, ±×¸®°í "projects.php"¿¡ ÀÖ´Â "forgot_password.php", ±×¸®°í the "title" Àμöµé·Î Àü´ÞÇÑ ÀÔ·ÂÀº »ç¿ëÀڵ鿡°Ô ¹ÝȯµÇ±â Àü¿¡ ÀûÀýÇÏ°Ô °É·¯ÁöÁö ¾Ê´Â´Ù. À̰ÍÀº Ãë¾àÇÑ »çÀÌÆ®ÀÇ ±ÇÇÑÀ¸·Î »ç¿ëÀÚÀÇ ºê¶ó¿ìÀú ¼¼¼Ç¿¡¼­ ÀÓÀÇÀÇ HTML°ú ½ºÅ©¸³Æ® Äڵ带 ½ÇÇàÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.

2. "preferences.php"¿¡ ÀÖ´Â "full_name", "sms_email", "list_refresh_rate", ±×¸®°í "emails_refresh_rate"¿¡ Àü´ÞµÈ ÀԷ°ªÀº »ç¿ëµÇ¾î Áö±â Àü¿¡ ÀûÀýÇÏ°Ô °É·¯ÁöÁö ¾Ê´Â´Ù. À̰ÍÀº ÀÓÀÇÀÇ HTML°ú ½ºÅ©¸³Æ® Äڵ带 ½ÇÇàÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖÀ¸¸ç, ¾ÇÀÇÀûÀÎ »ç¿ëÀÚ µ¥ÀÌÅͰ¡ º¸¿©Áú ¶§ Ãë¾àÇÑ »çÀÌÆ®ÀÇ ±ÇÇÑÀ¸·Î »ç¿ëÀÚÀÇ ºê¶ó¿ìÀú ¼¼¼Ç¿¡¼­ ¼öÇàµÇ°Ô µÈ´Ù.

3. EventumÀº µðÆúÆ® MD5·Î ¾ÏȣȭµÈ ÆÐ½º¿öµå¸¦ °¡Áö°í ºñ°ø½ÄÀûÀÎ µðÆúÆ® °ü¸®ÀÚ °èÁ¤(system-account@example.com)À» °¡Áö°í ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://secunia.com/advisories/13677/
http://www.cirt.net/advisories/eventum_xss.shtml
http://www.cirt.net/advisories/eventum_backdoor.shtml
http://bugs.mysql.com/bug.php?id=7551
http://bugs.mysql.com/bug.php?id=7552
http://www.osvdb.org/12605
http://www.osvdb.org/12606
http://www.osvdb.org/12607
http://www.osvdb.org/12608
http://www.osvdb.org/12609

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
MySQL AB Eventum 1.1¿¡¼­ 1.3.1 ±îÁöÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ MySQL AB À¥ »çÀÌÆ®ÀÎ http://mysql.timesoft.cc/downloads/other/eventum/index.html ¿¡¼­ ¹®Á¦°¡ ÇØ°áµÈ »õ ¹öÀü(1.4 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL 12133 (SecurityFocus)
°ü·Ã URL 18713,18714,18715,18716 (ISS)