English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21777
À§Çèµµ 20
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç Winmail ¼­¹ö´Â ´ÙÁßÀÇ ½ºÅ©¸³Æ®µé¿¡ ÀÖ´Â °æ·Î¸í ³ëÃâ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Winmail ¼­¹ö´Â Microsoft Windows Ç÷§ÆûµéÀ» À§ÇÑ È®À强ÀÖ´Â º¸¾È ±â´ÉµéÀ» °®Ãá »ó¿ë ¸ÞÀÏ ¼­¹öÀÌ´Ù. Winmail ¼­¹ö ¹öÀü 4.0 (build 1112)À» Æ÷ÇÔÇÑ ¿©·¯ ¹öÀüµéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¾î¶² ½Ã½ºÅÛ Á¤º¸¸¦ ³ëÃâ½ÃÄÑ º¼ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. admin/chgpwd.php, admin/domain.php, ȤÀº admin/user.php ½ºÅ©¸³Æ®µé·Î Àß Á¶ÀÛµÈ HTTP ¿äûÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â Ãë¾àÇÑ ¼­¹ö°¡ ¼³Ä¡ °æ·Î¸¦ Æ÷ÇÔÇÏ°í ÀÖ´Â ¿¡·¯ ¸Þ½ÃÁö¸¦ ¹ÝȯÇÏ°Ô ÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://secunia.com/advisories/13438/
http://www.osvdb.org/12336
http://www.osvdb.org/12337
http://www.osvdb.org/12338

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
AMAX Information Technologies »ç, Winmail ¼­¹ö ¹öÀü 4.0 (build 1112)À» Æ÷ÇÔÇÑ ¿©·¯ ¹öÀüµé
Microsoft Windows Any version
ÇØ°áÃ¥ "winmail_php.ini" ±¸¼º ÆÄÀÏ¿¡¼­ "display_errors = Off"¸¦ ¼³Á¤ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL 18427 (ISS)