English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22067
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç MS Site À¥¼­¹ö´Â Á¤º¸ ³ëÃâ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù.
Site Site À¥¼­¹ö 3.0 ¼³Ä¡½Ã ³»Àå LDAP ¼­ºñ½º¿¡ ÀÇÇØ »ç¿ëµÇ´Â LDAP_Anonymous »ç¿ëÀÚ °èÁ¤ÀÌ »ý¼ºµÈ´Ù. ºÒÇàÈ÷µµ ±× °èÁ¤¿¡ ´ëÇÑ ÆÐ½º¿öµå´Â 'LdapPassword_1'·Î ¼³Á¤µÇ¾î ÀÖ´Ù. ±×¸®°í /SiteServer/Admin/ °¡»ó µð·ºÅ丮¿¡ ÀÖ´Â °ü¸®¿ë ÆäÀÌÁöµéÀº 'LDAP_AnonymousUser' °èÁ¤À» ÀÌ¿ëÇÏ¿© ¾×¼¼½ºµÇ¾î Áú ¼ö ÀÖ´Ù. ±×·¯ÇÑ ÆäÀÌÁöµéÀº Áß¿äÇÑ Á¤º¸µéÀ» Æ÷ÇÔÇϰí ÀÖ´Ù.

¿¹µéµé¾î:

- http://target.com/SiteServer/Admin/knowledge/dsmgr/users/GroupManager.asp
- http://target.com/SiteServer/Admin/knowledge/dsmgr/users/UserManager.asp

ÀÌ ÆäÀÌÁöµéÀº LDAP »ç¿ëÀÚµé°ú ±×·ìµéÀ» »ý¼º, ¼öÁ¤, »èÁ¦ÇÒ ¼ö ÀÖ´Ù. ÀÓÀÇÀÇ »ç¿ëÀÚµéÀ» Ãß°¡Çϰí ÀÓÀÇÀÇ (Admin ±×·ìÀ» Æ÷ÇÔÇÑ) ±×·ìµé¿¡ »ý¼ºµÈ »ç¿ëÀÚµéÀ» Æ÷ÇÔ½Ãų ¼ö ÀÖ´Ù. ¾Ë¸²: À̰ÍÀº À©µµ¿ìÁî NT »ç¿ëÀÚ/±×·ì °ú´Â ´Ù¸£¸ç, LDAP ¿µ¿ª¿¡ ÇÑÁ¤µÈ´Ù. µû¶ó¼­ ¿Â¶óÀÎ À¥ ¾îÇø®ÄÉÀ̼ǿ¡ ÇÑÁ¤µÈ´Ù.

- http://target.com/SiteServer/Admin/knowledge/persmbr/vs.asp
- http://target.com/SiteServer/Admin/knowledge/persmbr/VsTmPr.asp
- http://target.com/SiteServer/Admin/knowledge/persmbr/VsLsLpRd.asp
- http://target.com/SiteServer/Admin/knowledge/persmbr/VsPrAuoEd.asp

ÀÌ ÆäÀÌÁöµéÀº ´Ù¾çÇÑ LDAP ¼­ºñ½º¿Í Backend ¼³Á¤ ÀμöµéÀ» ³ëÃâ½ÃŲ´Ù.

Ãë¾àÇÑ Ç÷§Æû:
Site Server version 3.0
ÇØ°áÃ¥ Site Server 3.0¿¡ ´ëÇÑ SP4 ÀÌ»óÀ» ¼³Ä¡ÇØ¾ß ÇÑ´Ù. ±×¸®°í Àΰ¡µÇÁö ¾ÊÀº È£½ºÆ®µé°ú »ç¿ëÀڵ鿡 ÀÇÇÑ /SiteServer/Admin/ µð·ºÅ丮·ÎÀÇ Á¢±ÙÀ» Â÷´ÜÇØ¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2002-1769 (CVE)
°ü·Ã URL 3998 (SecurityFocus)
°ü·Ã URL 8048 (ISS)