English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21246
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥¼­¹ö¿¡ ¼³Ä¡µÈ SquirrelMail ÆÐŰÁö´Â Cross-Site Scripting °ø°Ý(2)¿¡ Ãë¾àÇÏ´Ù. SquirrelMailÀº PHP·Î Á¦ÀÛµÈ À¥ ¸ÞÀÏ ÆÐŰÁöÀÌ´Ù. SquirrelMail ¹öÀü 1.2.10 ÀÌÇϵ鿡 ÀÖ´Â Cross-Site Scripting (XSS) Ãë¾àÁ¡Àº ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ read_body.phpÀ» ÅëÇØ ´Ù¸¥ À¥ »ç¿ëÀÚµéÀÇ ±ÇÇÑÀ¸·Î ½ºÅ©¸³Æ®¸¦ ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
read_body.php ½ºÅ©¸³Æ®´Â 'filter_dir' ¿Í 'mailbox'¿¡ ´ëÇÑ »ç¿ëÀÚ Á¦°ø ÀԷ°ªÀ» °É·¯³»Áö ¾Ê¾Æ Cross-Site Scripting °ø°Ýµé¿¡ Ãë¾àÇÏ´Ù. °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿©, HTML email¿¡ ³»Àå ½ºÅ©¸³Æ® Äڵ带 ³Ö°í Ãë¾àÇÑ Å¬¶óÀÌ¾ðÆ®¿¡ ÀÇÇØ ÀÐÇôÁö°Ô ÇÏ´Â ¹æ¹ýÀ¸·Î ÀÓÀÇÀÇ ½ºÅ©¸³Æ®¸¦ ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://marc.theaimsgroup.com/?l=bugtraq&m=103893844126484&w=2
http://marc.theaimsgroup.com/?l=bugtraq&m=103911130503272&w=2
http://marc.theaimsgroup.com/?l=bugtraq&m=104004924002662&w=2

* ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î:
SquirrelMail 1.2.10 ÀÌÇÏ
ÇØ°áÃ¥ ºñ·Ï ÀÌ °áÇÔ¿¡ ´ëÇÑ ¾÷±×·¹À̵åµéÀÌ ¸±¸®Áî µÇ¾úÁö¸¸, ÃÖ±Ù¿¡ ¶Ç ´Ù¸¥ º¸¾È»óÀÇ °áÇÔµéÀÌ ¹ß°ßµÇ¾î ¿Ô´Ù. SquirrelMail ÆÐŰÁöµéÀÇ °ø½Ä À¥ »çÀÌÆ®ÀÎ http://www.squirrelmail.org/ ·ÎºÎÅÍ SquirrelMailÀÇ °¡Àå ÃֽйöÀü (1.4.0 ÀÌ»ó)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2002-1341 (CVE)
°ü·Ã URL 6302 (SecurityFocus)
°ü·Ã URL (ISS)