English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21627
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç ProductCart ¼ÒÇÁÆ®¿þ¾î´Â ´ÙÁßÀÇ ÀÔ·Â °ËÁõ Ãë¾àÁ¡µé(1)¿¡ Ãë¾àÇÏ´Ù. ProductCart´Â Microsoft Windows ¿î¿µÃ¼Á¦µéÀ» À§ÇÑ ASP·Î Á¦ÀÛµÈ ÀüÀÚ»ó°Å·¡ Shopping Cart ÇÁ·Î±×·¥ÀÌ´Ù. ProductCart 1.0¿¡¼­ 2.0±îÁöÀÇ ¹öÀüµéÀº ´ÙÁßÀÇ ÀÔ·Â °ËÁõ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀڵ鿡 ÀÇÇØ Á¤º¸ ³ëÃâ, Cross-Site Scripting ±×¸®°í SQL ÁÖÀÔ °ø°ÝµéÀ» ¼öÇàÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.

1) ProductCart 1.0¿¡¼­ 2.0±îÁöÀÇ ¹öÀüµé¿¡ ÀÖ´Â Á¤º¸ ³ëÃâ Ãë¾àÁ¡Àº ¾ÈÁ¤ÇÏÁö ¾ÊÀº Æ۹̼ÇÀ» °¡Áø EIPC.mdb µ¥ÀÌÅͺ£À̽º ÆÄÀÏ¿¡ ´ëÇÑ Àß Á¶ÀÛµÈ HTTP ¿äûÀ» º¸³¿À¸·Î½á ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ °ü¸®ÀÚÀÇ Æнº¿öµå ±×¸®°í °í°´ Á¤º¸¿Í °°Àº ¹Î°¨ÇÑ Á¤º¸¸¦ °¡Á®°¥ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
2) ProductCart 1.5¿¡¼­ 2.0±îÁöÀÇ ¹öÀüµé¿¡ ÀÖ´Â ´ÙÁßÀÇ SQL ÁÖÀÔ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ login.asp·ÎÀÇ idadmin Àμö¸¦ ÅëÇÑ admin Á¦¾îÆÇ¿¡ ´ëÇÑ ¾×¼¼½º ¾ò°Å³ª ȤÀº Custva.asp·ÎÀÇ Email Àμö¸¦ ÅëÇÑ ´Ù¸¥ ±ÇÇÑÀ» ¾ò¾î³»µµ·Ï ÇØ ÁØ´Ù.
3) ProductCart 1.5 ÀÌÇÏÀÇ ¹öÀüµé¿¡ ÀÖ´Â msg.aspÀÇ Cross-Site Scripting (XSS) Ãë¾àÁ¡Àº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ message Àμö¸¦ ÅëÇØ ÀÓÀÇÀÇ À¥ ½ºÅ©¸³Æ®¸¦ ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securiteam.com/windowsntfocus/5DP0420AKG.html
http://archives.neohapsis.com/archives/bugtraq/2003-07/0030.html
http://archives.neohapsis.com/archives/bugtraq/2003-07/0064.html
http://archives.neohapsis.com/archives/bugtraq/2003-07/0113.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
EarlyImpact, ProductCart 1.0¿¡¼­ 2.0±îÁöÀÇ ¹öÀüµé
Microsoft Windows Any version
ÇØ°áÃ¥ EarlyImpact À¥ »çÀÌÆ®ÀÎ http://www.earlyimpact.com ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â ProductCartÀÇ °¡Àå ÃֽŠ¹öÀü(2.0 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2003-0522,CVE-2003-0523 (CVE)
°ü·Ã URL 8103,8105,8108,8112 (SecurityFocus)
°ü·Ã URL 12515,12517,12524 (ISS)