English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21294
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥¼­¹ö¿¡ ¼³Ä¡µÈ PostNuke ¿¡´Â "openwindow.php" ½ºÅ©¸³Æ® »óÀÇ Cross-Site Scripting Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
Francisco Burzi ¿¡ ÀÇÇØ °³¹ßµÈ PostNuke´Â MySQL µ¥ÀÌÅͺ£À̽º¸¦ »ç¿ëÇÏ´Â PHP ÄÁÅÙÆ® °ü¸® ½Ã½ºÅÛÀÌ´Ù. ÀÌ PostNukeÀÇ ¹öÀü 0.7.2.6 ¿¡´Â "openwindow.php" ½ºÅ©¸³Æ® »óÀÇ ºÎÀûÀýÇÑ ÀÔ·Â ÇÊÅ͸µÀ¸·Î ÀÎÇÏ¿© Cross-Site Scripting Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ¾ÇÀÇÀûÀÎ °ø°ÝÀÚµéÀº ´ÙÀ½°ú °°ÀÌ ¾ÇÀÇÀûÀÎ ½ºÅ©¸³Æ®¸¦ »ðÀÔÇÏ¿© Àß Á¶ÀÛµÈ URL ¸µÅ©¸¦ ¼­¹ö¿¡ Àü´ÞÇÔÀ¸·Î½á, ÇØ´ç ¼­¹öÀÇ ±ÇÇÑÀ¸·Î ´ë»ó »ç¿ëÀÚÀÇ À¥ ºê¶ó¿ìÀú »ó¿¡¼­ ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡Àº ´ë»ó ½Ã½ºÅÛÀÇ ÄíŰ(cookie) ±â¹Ý ÀÎÁõÁ¤º¸µéÀ» ÈÉÄ¡±â À§ÇØ ÀÌ¿ëµÉ ¼ö ÀÖ´Ù. Postnuke ¹öÀü 0.7.2.6 ¿¡´Â "Downloads", "Web_Links" ¸ðµâ »óÀÇ Cross-Site Scripting Ãë¾àÁ¡µéµµ Á¸ÀçÇÑ´Ù.

http://[target]/postnuke0726/modules.php?op=modload&name=Downloads&file=index&req=ratedownload&ttitle=x&lid=>[xss code here]
http://[target]/postnuke0726/modules.php?op=modload&name=Downloads&file=index&req=search&query=>[xss code here]
http://[target]/postnuke0726/modules.php?op=modload&name=Web_Links&file=index&req=search&query=>[xss code here]
http://[target]/postnuke0726/javascript/openwindow.php?hlpfile=x<html><body>[xss code here]
http://[target]/postnuke0726/javascript/openwindow.php?hlpfile=x<html><body%20onload=alert(document.cookie);>

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/fulldisclosure/2004-03/2336.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
PostNuke Phoenix 0.7.2.6
UNIX/Linux ¸ðµç ¹öÀü
Windows ¸ðµç ¹öÀü
ÇØ°áÃ¥ 2014³â 6¿ù ÇöÀç ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ ÆÐÄ¡³ª ¾÷±×·¹À̵å´Â ³ª¿Í ÀÖÁö ¾Ê´Ù.
°ü·Ã URL CVE-2004-1957 (CVE)
°ü·Ã URL 10191 (SecurityFocus)
°ü·Ã URL 15934 (ISS)