| 
   
            
 	            | Ãë¾àÁ¡ID | 22340 |   
 	            | À§Çèµµ | 30 |  
 	            | Æ÷Æ® | 4096,32000 |  	
 	            | ÇÁ·ÎÅäÄÝ | TCP |  	
 	            | ºÐ·ù | WWW |  	
 	            | »ó¼¼¼³¸í | ÇØ´ç È£½ºÆ®´Â ´ÙÁßÀÇ Ãë¾àÁ¡µéÀ» °¡Áø IceWarp/Merak À¥ ¸ÞÀÏ ¼¹öÀÇ ¾î¶² ¹öÀüÀ» °¡µ¿ ÁßÀÌ´Ù. Merak Mail ¼¹ö´Â °í¼º´ÉÀÇ Windows ±â¹ÝÀÇ º¸¾È ÀÎÅÍ³Ý ¸ÞÀÏ ¼¹ö ¼ÒÇÁÆ®¿þ¾îÀÌÀÚ ±×·ì¿þ¾î ¼¹öÀÌ´Ù. IceWarp À¥ ¸ÞÀÏ 7.5.2 ÀÌÇÏÀÇ ¹öÀüµéÀ» °¡Áø Merak Mail ¼¹ö 7.5.2 ÀÌÇÏÀÇ ¹öÀüµéÀº ´ÙÀ½°ú °°Àº ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù: 
 1) ´ÙÁßÀÇ Cross-Site Scripting Ãë¾àÁ¡µé
 2) HTML ÁÖÀÔ Ãë¾àÁ¡
 3) PHP ¼Ò½º ÄÚµå ³ëÃâ Ãë¾àÁ¡
 4) SQL ÁÖÀÔ Ãë¾àÁ¡
 
 * Âü°í »çÀÌÆ®:
 http://www.securitytracker.com/alerts/2004/Aug/1010969.html
 http://www.osvdb.org/9037
 http://www.osvdb.org/9038
 http://www.osvdb.org/9039
 http://www.osvdb.org/9040
 http://www.osvdb.org/9041
 http://www.osvdb.org/9042
 http://www.osvdb.org/9043
 http://www.osvdb.org/9044
 http://www.osvdb.org/9045
 
 * ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
 IceWarp Software, IceWarp Web Mail 5.2.7 ÀÌÇÏÀÇ ¹öÀüµé
 Merak Mail Server, »ç, Merak Mail Server 7.5.2 ÀÌÇÏÀÇ ¹öÀüµé
 Microsoft Windows Any version
 |  	
 	            | ÇØ°áÃ¥ | Merak Mail Server ¼ÒÇÁÆ®¿þ¾î ´Ù¿î·Îµå À¥ ÆäÀÌÁöÀÎ http://merak-mail-server.smartcode.com/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â Merak Webmail / IceWarp Web Mail (5.2.8 ȤÀº ÀÌÈÄ) ȤÀº Merak Mail Server (7.5.2 ȤÀº ÀÌÈÄ)ÀÇ °¡Àå ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |  	
 	            | °ü·Ã URL | CVE-2004-1719,CVE-2004-1720,CVE-2004-1721,CVE-2004-1722 (CVE) |  	
 	            | °ü·Ã URL | 10966 (SecurityFocus) |  
 	            | °ü·Ã URL | 17022,17024,17027,17029 (ISS) |  |