English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21480
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç Gallery ¼ÒÇÁÆ®¿þ¾î´Â ´ÙÁßÀÇ ¿ø°Ý Ãë¾àÁ¡µé¿¡ Ãë¾àÇÑ °ÍÀ¸·Î ³ªÅ¸³­´Ù. Bharat Mediratta Gallery´Â PHP¸¦ Áö¿øÇÏ´Â À¥ »çÀÌÆ® »ó¿¡¼­ »çÁø °ü¸®¸¦ À§ÇØ »ç¿ëÇÏ´Â À¥ ±â¹ÝÀÇ ¼ÒÇÁÆ®¿þ¾î Á¦Ç°ÀÌ´Ù. Gallery 1.3.4-pl1, 1.4.4-pl2, ±×¸®°í 2.0 Alpha ¹öÀüµéÀº ´ÙÀ½°ú °°Àº ´ÙÁßÀÇ Cross-Site Scripting°ú Á¤º¸ ³ëÃâ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù:

- Gallery 1.3.4-pl1¿¡ ÀÖ´Â ´ÙÁßÀÇ Cross-Site Scripting Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ (1) add_comment.phpÀÇ index Çʵå, slideshow_low.phpÀÇ (2) set_albumName, (3) slide_index, (4) slide_full, (5) slide_loop, (6) slide_pause, (7) slide_dir Çʵåµé, ȤÀº (8) search.phpÀÇ username Çʵ带 ÅëÇÏ¿© ÀÓÀÇÀÇ À¥ ½ºÅ©¸³Æ®¿Í HTMLÀ» ÁÖÀÔ½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
- Gallery 1.4.4-pl2ÀÇ login.php¿¡ ÀÖ´Â Cross-Site Scripting Ãë¾àÁ¡Àº ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ username Çʵ带 ÅëÇÏ¿© ÀÓÀÇÀÇ À¥ ½ºÅ©¸³Æ®¿Í HTMLÀ» ÁÖÀÔ½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
- Gallery 2.0 Alpha¿¡ ÀÖ´Â Cross-Site Scripting Ãë¾àÁ¡Àº ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ g2_form[subject] Çʵ带 ÅëÇÏ¿© ÀÓÀÇÀÇ À¥ ½ºÅ©¸³Æ®¿Í HTMLÀ» ÁÖÀÔ½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
- Gallery 2.0 Alpha¿¡¼­ GalleryÀÇ ¾î¶² Á¶°Ç ÇÏ¿¡ Ãë¾àÇÑ GalleryÀÇ ¼³Ä¡ °æ·Î¸íÀ» Æ÷ÇÔÇϰí ÀÖ´Â ¿¡·¯ ¸Þ½ÃÁö¸¦ ¹ÝȯÇÏ´Â °ÍÀ¸·Î º¸°íµÇ¾î ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0031.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Bharat Mediratta, Gallery 1.3.4-pl1
Bharat Mediratta, Gallery 1.4.4-pl2
Bharat Mediratta, Gallery 2.0 Alpha
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ Gallery Project À¥ »çÀÌÆ®ÀÎ http://gallery.menalto.com/modules.php?op=modload&name=News&file=index ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â GalleryÀÇ °¡Àå ÃֽйöÀü(1.4.4-pl5 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2005-0219,CVE-2005-0220,CVE-2005-0221 (CVE)
°ü·Ã URL 12286,12292 (SecurityFocus)
°ü·Ã URL 18938 (ISS)