| Ãë¾àÁ¡ID |
21441 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
CGI |
| »ó¼¼¼³¸í |
ÇØ´ç WordPress ÇÁ·Î±×·¥Àº wp-login.php ½ºÅ©¸³Æ®¿¡ ÀÖ´Â Cross-Site Scripting °áÇÔ¿¡ Ãë¾àÇÏ´Ù. WordPress ´Â MySQL µ¥ÀÌÅͺ£À̽º¸¦ »ç¿ëÇÏ´Â PHP ±â¹ÝÀÇ ÃâÆÇ(publication) ÇÁ·Î±×·¥À¸·Î¼, ¹«·á·Î »ç¿ë °¡´ÉÇÑ ÇÁ·Î±×·¥ÀÌ´Ù. WordPress 1.2.1 ÀÌÇÏÀÇ ¹öÀüµéÀº wp-login.php, bookmarklet.php, catagories.php, edit.php ±×¸®°í edit-comments.php ½ºÅ©¸³Æ®µé¿¡ ÀÖ´Â ´ÙÁßÀÇ Cross-Site Scripting °áÇԵ鿡 Ãë¾àÇÏ´Ù. ÀÌ Cross-Site Scripting ¹®Á¦Á¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¾ÇÀÇÀûÀÎ HTML°ú ½ºÅ©¸³Æ® Äڵ带 Æ÷ÇÔÇÏ´Â Ãë¾àÇÑ ¾îÇø®ÄÉÀ̼ÇÀ¸·ÎÀÇ ¾ÇÀÇÀûÀÎ ¸µÅ©(link)¸¦ ¸¸µé°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. ¸¸¾à ÀÌ ¸µÅ©¸¦ µû¶ó°¡°Ô µÈ´Ù¸é ¾ÇÀÇÀûÀÎ Äڵ尡 Èñ»ýÀÚÀÇ À¥ ºê¶ó¿ìÀú¿¡¼ ½ÇÇàµÉ ¼ö ÀÖ´Ù. À̰ÍÀº ¿µÇâÀ» ¹Þ´Â À¥ »çÀÌÆ®ÀÇ º¸¾È ±ÇÇÑÀ» °¡Áö°í ÇàÇØÁö¸ç ÄíŰ ±â¹ÝÀÇ ÀÎÁõ ½Å¿ëÁ¤º¸¸¦ »©³»°Å³ª ´Ù¸¥ °ø°ÝµéÀÇ ¼öÇàÀ» Çã¿ëÇÒ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/bugtraq/2004-09/0382.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Matthew Mullenweg, WordPress 1.2.1 ÀÌÇÏÀÇ ¹öÀüµé Microsoft Windows Any version Linux Any version Unix Any version |
| ÇØ°áÃ¥ |
WordPress À¥ »çÀÌÆ®ÀÎ http://wordpress.org/download/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â WordPressÀÇ °¡Àå ÃֽйöÀü(1.2.2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
Gentoo LinuxÀÇ °æ¿ì: ´ÙÀ½ Gentoo Linux Security Advisory GLSA 200410-12¸¦ ÂüÁ¶ÇÏ¿© WordPressÀÇ °¡Àå ÃֽйöÀü(1.2.2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.gentoo.org/security/en/glsa/glsa-200410-12.xml |
| °ü·Ã URL |
CVE-2004-1559 (CVE) |
| °ü·Ã URL |
11268 (SecurityFocus) |
| °ü·Ã URL |
17532 (ISS) |
|