Ãë¾àÁ¡ID |
21541 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç Mambo Open Source´Â Cross-Site Scripting ¹× ÆÄÀÏ ¾÷·Îµå Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. Mambo Open Source(¿¹Àü¿¡´Â Mambo Site Server·Î ºÒ¸²)´Â ÀÎÅÍ³Ý Æ÷ÅÐ ¹× ÄÜÅÙÃ÷ °ü¸® ¼ÒÇÁÆ®¿þ¾îÀÌ´Ù. Mambo Open Source 4.0.12 BETA ÀÌÇÏÀÇ ¹öÀüµéÀº µÎ°¡Áö Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù:
1) sectionswindow.php, gallery.php, navigation.php, uploadimage.php, view.php, upload.php, mambosimple.php, upload.php, emailarticle.php, emailfaq.php and emailnews.php ½ºÅ©¸³Æ®µé·Î °Ç³×Áø »ç¿ëÀÚ Á¦°ø ÀÔ·ÂÀº »ç¿ëÀڵ鿡°Ô ¹ÝȯµÇ±â Àü¿¡ ÀûÀýÇÏ°Ô ÇÊÅ͸µµÇÁö ¾Ê´Â´Ù. ÀÌ´Â Ãë¾àÇÑ »çÀÌÆ®ÀÇ È¯°æ ÇÏ¿¡¼ »ç¿ëÀÚÀÇ ºê¶ó¿ìÀú ¼¼¼ÇÀ¸·Î ÀÓÀÇÀÇ HTML°ú ½ºÅ©¸³Æ® Äڵ带 ½ÇÇàÇϴµ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù. 2) upload.php, administrator/upload.php, ±×¸®°í administrator/gallery/uploadimage.php ½ºÅ©¸³Æ®µé¿¡ ÀÖ´Â ÆÄÀÏ ¾÷·Îµå Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ½Ã½ºÅÛ¿¡ ÀÓÀÇÀÇ ÆÄÀϵéÀ» ¾÷·Îµå ÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡µéÀ» µµ¿ëÇÏ¿© Ãë¾àÇÑ ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ PHP ½ºÅ©¸³Æ® Äڵ带 ¾÷·ÎµåÇÏ°í ½ÇÇàÇÒ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/bugtraq/2003-01/0075.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Miro Construct Pty »ç, Mambo Site Server 4.0.12BETA ÀÌÇÏÀÇ ¹öÀüµé ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
MamboForge À¥ »çÀÌÆ®ÀÎ http://sourceforge.net/projects/mambo/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â Mambo Open SourceÀÇ °¡Àå ÃֽŠ¹öÀü(4.0.12 BETA2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2003-1204 (CVE) |
°ü·Ã URL |
6571,6572 (SecurityFocus) |
°ü·Ã URL |
11050,11051 (ISS) |
|