| Ãë¾àÁ¡ID |
21248 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
CGI |
| »ó¼¼¼³¸í |
ÇØ´ç À¥¼¹ö¿¡ ¼³Ä¡µÈ PostNuke´Â user.php ¶Ç´Â modules.php¸¦ ÅëÇÑ Cross-Site Scripting(XSS) °ø°Ý¿¡ Ãë¾àÇÏ´Ù. PostNuke´Â MySQL µ¥ÀÌÅͺ£À̽º¸¦ »ç¿ëÇÏ´Â ÄÁÅÙÆ®(content) °ü¸® ½Ã½ºÅÛÀÌ´Ù. ÀÌ Cross-Site Scripting(XSS) °ø°ÝÀº URI ÆÄ¶ó¹ÌÅÍ¿¡ Àü´ÞµÇ´Â ¹®ÀÚ¿À» ÃæºÐÈ÷ ó¸®ÇÏÁö ¸øÇÏ´Â PostNuke »óÀÇ °áÇÔÀ» ÀÌ¿ëÇÑ´Ù. '?op' ÆÄ¶ó¹ÌÅÍ¿¡ ½ºÅ©¸³Æ®¸¦ »ðÀÔÇÑ ¾ÇÀÇÀûÀÎ URL ¸µÅ©¸¦ modules.php ¶Ç´Â user.php ½ºÅ©¸³Æ®¿¡ Àü´ÞÇÔÀ¸·Î½á, ¿ø°ÝÁö °ø°ÝÀÚµéÀº »ðÀÔµÈ ½ºÅ©¸³Æ®°¡ À¥ Ŭ¶óÀÌ¾ðÆ® ºê¶ó¿ìÀú¸¦ ÅëÇØ¼ ½ÇÇàµÇµµ·Ï ÇÒ ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡À» µµ¿ëÇϸé, ÄíŰ(cookie) ±â¹ÝÀÇ ÀÎÁõ Á¤º¸¸¦ ÈÉÄ¡°Å³ª À¥ ÄÁÅÙÆ®¸¦ °¡·Îç ¼ö ÀÖ´Ù. ¾Æ·¡ ¸®½ºÆ®µÈ °Íó·³ ¿µÇâÀ» ¹Þ´Â ¼¹ö¿¡ ´ëÇØ ÀÌ Ãë¾àÁ¡À» Å×½ºÆ®ÇØ º¼ ¼ö ÀÖ´Ù.
http://www.server.com/user.php?op=confirmnewuser&module=NS-NewUser&uname=%22%3E%3Cimg%20src=%22javascript:alert(document.cookie);%22%3E&email=lucas@pelucas.com http://www.server.com/modules.php?op=modload&name=FAQ&file=index&myfaq=yes&id_cat=1&categories=%3Cimg%20src=javascript:alert(document.cookie);%3E&parent_id=0 http://www.server.com/modules.php?letter=%22%3E%3Cimg%20src=javascript:alert(document.cookie);%3E&op=modload&name=Members_List&file=index
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/archive/1/325069
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: PostNuke Phoenix 0.7.2.3 UNIX/Linux ¸ðµç ¹öÀü Windows ¸ðµç ¹öÀü |
| ÇØ°áÃ¥ |
´ÙÀ½ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© PostNuke Phoenix (v7.2.4 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù. http://en.kbdown.com/32551.html
ÀÓÀÇ Á¶Ä¡¹æ¹ýÀ¸·Î, ´ÙÀ½ÀÇ ºñ°ø½ÄÀûÀÎ Àӽà Á¶Ä¡¹æ¹ýÀÌ David F.Madrid ¿¡ ÀÇÇØ¼ Á¦°øµÇ¾ú´Ù. $good_var=eregi_replace("[^a-z0-9]+)and([^a-z0-9]+)","0",$var); |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
7898,7901 (SecurityFocus) |
| °ü·Ã URL |
12291,12292 (ISS) |
|