English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21541
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç Mambo Open Source´Â Cross-Site Scripting ¹× ÆÄÀÏ ¾÷·Îµå Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. Mambo Open Source(¿¹Àü¿¡´Â Mambo Site Server·Î ºÒ¸²)´Â ÀÎÅÍ³Ý Æ÷ÅÐ ¹× ÄÜÅÙÃ÷ °ü¸® ¼ÒÇÁÆ®¿þ¾îÀÌ´Ù. Mambo Open Source 4.0.12 BETA ÀÌÇÏÀÇ ¹öÀüµéÀº µÎ°¡Áö Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù:

1) sectionswindow.php, gallery.php, navigation.php, uploadimage.php, view.php, upload.php, mambosimple.php, upload.php, emailarticle.php, emailfaq.php and emailnews.php ½ºÅ©¸³Æ®µé·Î °Ç³×Áø »ç¿ëÀÚ Á¦°ø ÀÔ·ÂÀº »ç¿ëÀڵ鿡°Ô ¹ÝȯµÇ±â Àü¿¡ ÀûÀýÇÏ°Ô ÇÊÅ͸µµÇÁö ¾Ê´Â´Ù. ÀÌ´Â Ãë¾àÇÑ »çÀÌÆ®ÀÇ È¯°æ ÇÏ¿¡¼­ »ç¿ëÀÚÀÇ ºê¶ó¿ìÀú ¼¼¼ÇÀ¸·Î ÀÓÀÇÀÇ HTML°ú ½ºÅ©¸³Æ® Äڵ带 ½ÇÇàÇϴµ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.
2) upload.php, administrator/upload.php, ±×¸®°í administrator/gallery/uploadimage.php ½ºÅ©¸³Æ®µé¿¡ ÀÖ´Â ÆÄÀÏ ¾÷·Îµå Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ½Ã½ºÅÛ¿¡ ÀÓÀÇÀÇ ÆÄÀϵéÀ» ¾÷·Îµå ÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡µéÀ» µµ¿ëÇÏ¿© Ãë¾àÇÑ ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ PHP ½ºÅ©¸³Æ® Äڵ带 ¾÷·ÎµåÇÏ°í ½ÇÇàÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2003-01/0075.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Miro Construct Pty »ç, Mambo Site Server 4.0.12BETA ÀÌÇÏÀÇ ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ MamboForge À¥ »çÀÌÆ®ÀÎ http://sourceforge.net/projects/mambo/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â Mambo Open SourceÀÇ °¡Àå ÃֽŠ¹öÀü(4.0.12 BETA2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2003-1204 (CVE)
°ü·Ã URL 6571,6572 (SecurityFocus)
°ü·Ã URL 11050,11051 (ISS)