English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22340
À§Çèµµ 30
Æ÷Æ® 4096,32000
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®´Â ´ÙÁßÀÇ Ãë¾àÁ¡µéÀ» °¡Áø IceWarp/Merak À¥ ¸ÞÀÏ ¼­¹öÀÇ ¾î¶² ¹öÀüÀ» °¡µ¿ ÁßÀÌ´Ù. Merak Mail ¼­¹ö´Â °í¼º´ÉÀÇ Windows ±â¹ÝÀÇ º¸¾È ÀÎÅÍ³Ý ¸ÞÀÏ ¼­¹ö ¼ÒÇÁÆ®¿þ¾îÀÌÀÚ ±×·ì¿þ¾î ¼­¹öÀÌ´Ù. IceWarp À¥ ¸ÞÀÏ 7.5.2 ÀÌÇÏÀÇ ¹öÀüµéÀ» °¡Áø Merak Mail ¼­¹ö 7.5.2 ÀÌÇÏÀÇ ¹öÀüµéÀº ´ÙÀ½°ú °°Àº ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù:

1) ´ÙÁßÀÇ Cross-Site Scripting Ãë¾àÁ¡µé
2) HTML ÁÖÀÔ Ãë¾àÁ¡
3) PHP ¼Ò½º ÄÚµå ³ëÃâ Ãë¾àÁ¡
4) SQL ÁÖÀÔ Ãë¾àÁ¡

* Âü°í »çÀÌÆ®:
http://www.securitytracker.com/alerts/2004/Aug/1010969.html
http://www.osvdb.org/9037
http://www.osvdb.org/9038
http://www.osvdb.org/9039
http://www.osvdb.org/9040
http://www.osvdb.org/9041
http://www.osvdb.org/9042
http://www.osvdb.org/9043
http://www.osvdb.org/9044
http://www.osvdb.org/9045

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
IceWarp Software, IceWarp Web Mail 5.2.7 ÀÌÇÏÀÇ ¹öÀüµé
Merak Mail Server, »ç, Merak Mail Server 7.5.2 ÀÌÇÏÀÇ ¹öÀüµé
Microsoft Windows Any version
ÇØ°áÃ¥ Merak Mail Server ¼ÒÇÁÆ®¿þ¾î ´Ù¿î·Îµå À¥ ÆäÀÌÁöÀÎ http://merak-mail-server.smartcode.com/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â Merak Webmail / IceWarp Web Mail (5.2.8 ȤÀº ÀÌÈÄ) ȤÀº Merak Mail Server (7.5.2 ȤÀº ÀÌÈÄ)ÀÇ °¡Àå ÃֽŠ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2004-1719,CVE-2004-1720,CVE-2004-1721,CVE-2004-1722 (CVE)
°ü·Ã URL 10966 (SecurityFocus)
°ü·Ã URL 17022,17024,17027,17029 (ISS)