| Ãë¾àÁ¡ID |
22067 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
WWW |
| »ó¼¼¼³¸í |
ÇØ´ç MS Site À¥¼¹ö´Â Á¤º¸ ³ëÃâ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Site Site À¥¼¹ö 3.0 ¼³Ä¡½Ã ³»Àå LDAP ¼ºñ½º¿¡ ÀÇÇØ »ç¿ëµÇ´Â LDAP_Anonymous »ç¿ëÀÚ °èÁ¤ÀÌ »ý¼ºµÈ´Ù. ºÒÇàÈ÷µµ ±× °èÁ¤¿¡ ´ëÇÑ ÆÐ½º¿öµå´Â 'LdapPassword_1'·Î ¼³Á¤µÇ¾î ÀÖ´Ù. ±×¸®°í /SiteServer/Admin/ °¡»ó µð·ºÅ丮¿¡ ÀÖ´Â °ü¸®¿ë ÆäÀÌÁöµéÀº 'LDAP_AnonymousUser' °èÁ¤À» ÀÌ¿ëÇÏ¿© ¾×¼¼½ºµÇ¾î Áú ¼ö ÀÖ´Ù. ±×·¯ÇÑ ÆäÀÌÁöµéÀº Áß¿äÇÑ Á¤º¸µéÀ» Æ÷ÇÔÇϰí ÀÖ´Ù.
¿¹µéµé¾î:
- http://target.com/SiteServer/Admin/knowledge/dsmgr/users/GroupManager.asp - http://target.com/SiteServer/Admin/knowledge/dsmgr/users/UserManager.asp
ÀÌ ÆäÀÌÁöµéÀº LDAP »ç¿ëÀÚµé°ú ±×·ìµéÀ» »ý¼º, ¼öÁ¤, »èÁ¦ÇÒ ¼ö ÀÖ´Ù. ÀÓÀÇÀÇ »ç¿ëÀÚµéÀ» Ãß°¡Çϰí ÀÓÀÇÀÇ (Admin ±×·ìÀ» Æ÷ÇÔÇÑ) ±×·ìµé¿¡ »ý¼ºµÈ »ç¿ëÀÚµéÀ» Æ÷ÇÔ½Ãų ¼ö ÀÖ´Ù. ¾Ë¸²: À̰ÍÀº À©µµ¿ìÁî NT »ç¿ëÀÚ/±×·ì °ú´Â ´Ù¸£¸ç, LDAP ¿µ¿ª¿¡ ÇÑÁ¤µÈ´Ù. µû¶ó¼ ¿Â¶óÀÎ À¥ ¾îÇø®ÄÉÀ̼ǿ¡ ÇÑÁ¤µÈ´Ù.
- http://target.com/SiteServer/Admin/knowledge/persmbr/vs.asp - http://target.com/SiteServer/Admin/knowledge/persmbr/VsTmPr.asp - http://target.com/SiteServer/Admin/knowledge/persmbr/VsLsLpRd.asp - http://target.com/SiteServer/Admin/knowledge/persmbr/VsPrAuoEd.asp
ÀÌ ÆäÀÌÁöµéÀº ´Ù¾çÇÑ LDAP ¼ºñ½º¿Í Backend ¼³Á¤ ÀμöµéÀ» ³ëÃâ½ÃŲ´Ù.
Ãë¾àÇÑ Ç÷§Æû: Site Server version 3.0 |
| ÇØ°áÃ¥ |
Site Server 3.0¿¡ ´ëÇÑ SP4 ÀÌ»óÀ» ¼³Ä¡ÇØ¾ß ÇÑ´Ù. ±×¸®°í Àΰ¡µÇÁö ¾ÊÀº È£½ºÆ®µé°ú »ç¿ëÀڵ鿡 ÀÇÇÑ /SiteServer/Admin/ µð·ºÅ丮·ÎÀÇ Á¢±ÙÀ» Â÷´ÜÇØ¾ß ÇÑ´Ù. |
| °ü·Ã URL |
CVE-2002-1769 (CVE) |
| °ü·Ã URL |
3998 (SecurityFocus) |
| °ü·Ã URL |
8048 (ISS) |
|