English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21248
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥¼­¹ö¿¡ ¼³Ä¡µÈ PostNuke´Â user.php ¶Ç´Â modules.php¸¦ ÅëÇÑ Cross-Site Scripting(XSS) °ø°Ý¿¡ Ãë¾àÇÏ´Ù.
PostNuke´Â MySQL µ¥ÀÌÅͺ£À̽º¸¦ »ç¿ëÇÏ´Â ÄÁÅÙÆ®(content) °ü¸® ½Ã½ºÅÛÀÌ´Ù. ÀÌ Cross-Site Scripting(XSS) °ø°ÝÀº URI ÆÄ¶ó¹ÌÅÍ¿¡ Àü´ÞµÇ´Â ¹®ÀÚ¿­À» ÃæºÐÈ÷ ó¸®ÇÏÁö ¸øÇÏ´Â PostNuke »óÀÇ °áÇÔÀ» ÀÌ¿ëÇÑ´Ù. '?op' ÆÄ¶ó¹ÌÅÍ¿¡ ½ºÅ©¸³Æ®¸¦ »ðÀÔÇÑ ¾ÇÀÇÀûÀÎ URL ¸µÅ©¸¦ modules.php ¶Ç´Â user.php ½ºÅ©¸³Æ®¿¡ Àü´ÞÇÔÀ¸·Î½á, ¿ø°ÝÁö °ø°ÝÀÚµéÀº »ðÀÔµÈ ½ºÅ©¸³Æ®°¡ À¥ Ŭ¶óÀÌ¾ðÆ® ºê¶ó¿ìÀú¸¦ ÅëÇØ¼­ ½ÇÇàµÇµµ·Ï ÇÒ ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡À» µµ¿ëÇϸé, ÄíŰ(cookie) ±â¹ÝÀÇ ÀÎÁõ Á¤º¸¸¦ ÈÉÄ¡°Å³ª À¥ ÄÁÅÙÆ®¸¦ °¡·Îç ¼ö ÀÖ´Ù. ¾Æ·¡ ¸®½ºÆ®µÈ °Íó·³ ¿µÇâÀ» ¹Þ´Â ¼­¹ö¿¡ ´ëÇØ ÀÌ Ãë¾àÁ¡À» Å×½ºÆ®ÇØ º¼ ¼ö ÀÖ´Ù.

http://www.server.com/user.php?op=confirmnewuser&module=NS-NewUser&uname=%22%3E%3Cimg%20src=%22javascript:alert(document.cookie);%22%3E&email=lucas@pelucas.com
http://www.server.com/modules.php?op=modload&name=FAQ&file=index&myfaq=yes&id_cat=1&categories=%3Cimg%20src=javascript:alert(document.cookie);%3E&parent_id=0
http://www.server.com/modules.php?letter=%22%3E%3Cimg%20src=javascript:alert(document.cookie);%3E&op=modload&name=Members_List&file=index

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/325069

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
PostNuke Phoenix 0.7.2.3
UNIX/Linux ¸ðµç ¹öÀü
Windows ¸ðµç ¹öÀü
ÇØ°áÃ¥ ´ÙÀ½ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© PostNuke Phoenix (v7.2.4 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù.
http://en.kbdown.com/32551.html

ÀÓÀÇ Á¶Ä¡¹æ¹ýÀ¸·Î, ´ÙÀ½ÀÇ ºñ°ø½ÄÀûÀÎ Àӽà Á¶Ä¡¹æ¹ýÀÌ David F.Madrid ¿¡ ÀÇÇØ¼­ Á¦°øµÇ¾ú´Ù.
$good_var=eregi_replace("[^a-z0-9]+)and([^a-z0-9]+)","0",$var);
°ü·Ã URL (CVE)
°ü·Ã URL 7898,7901 (SecurityFocus)
°ü·Ã URL 12291,12292 (ISS)