| Ãë¾àÁ¡ID |
21246 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
CGI |
| »ó¼¼¼³¸í |
ÇØ´ç À¥¼¹ö¿¡ ¼³Ä¡µÈ SquirrelMail ÆÐŰÁö´Â Cross-Site Scripting °ø°Ý(2)¿¡ Ãë¾àÇÏ´Ù. SquirrelMailÀº PHP·Î Á¦ÀÛµÈ À¥ ¸ÞÀÏ ÆÐŰÁöÀÌ´Ù. SquirrelMail ¹öÀü 1.2.10 ÀÌÇϵ鿡 ÀÖ´Â Cross-Site Scripting (XSS) Ãë¾àÁ¡Àº ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ read_body.phpÀ» ÅëÇØ ´Ù¸¥ À¥ »ç¿ëÀÚµéÀÇ ±ÇÇÑÀ¸·Î ½ºÅ©¸³Æ®¸¦ ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. read_body.php ½ºÅ©¸³Æ®´Â 'filter_dir' ¿Í 'mailbox'¿¡ ´ëÇÑ »ç¿ëÀÚ Á¦°ø ÀԷ°ªÀ» °É·¯³»Áö ¾Ê¾Æ Cross-Site Scripting °ø°Ýµé¿¡ Ãë¾àÇÏ´Ù. °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿©, HTML email¿¡ ³»Àå ½ºÅ©¸³Æ® Äڵ带 ³Ö°í Ãë¾àÇÑ Å¬¶óÀÌ¾ðÆ®¿¡ ÀÇÇØ ÀÐÇôÁö°Ô ÇÏ´Â ¹æ¹ýÀ¸·Î ÀÓÀÇÀÇ ½ºÅ©¸³Æ®¸¦ ½ÇÇà½Ãų ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://marc.theaimsgroup.com/?l=bugtraq&m=103893844126484&w=2 http://marc.theaimsgroup.com/?l=bugtraq&m=103911130503272&w=2 http://marc.theaimsgroup.com/?l=bugtraq&m=104004924002662&w=2
* ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î: SquirrelMail 1.2.10 ÀÌÇÏ |
| ÇØ°áÃ¥ |
ºñ·Ï ÀÌ °áÇÔ¿¡ ´ëÇÑ ¾÷±×·¹À̵åµéÀÌ ¸±¸®Áî µÇ¾úÁö¸¸, ÃÖ±Ù¿¡ ¶Ç ´Ù¸¥ º¸¾È»óÀÇ °áÇÔµéÀÌ ¹ß°ßµÇ¾î ¿Ô´Ù. SquirrelMail ÆÐŰÁöµéÀÇ °ø½Ä À¥ »çÀÌÆ®ÀÎ http://www.squirrelmail.org/ ·ÎºÎÅÍ SquirrelMailÀÇ °¡Àå ÃֽйöÀü (1.4.0 ÀÌ»ó)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
| °ü·Ã URL |
CVE-2002-1341 (CVE) |
| °ü·Ã URL |
6302 (SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|