Ãë¾àÁ¡ID |
22420 |
À§Çèµµ |
30 |
Æ÷Æ® |
10000 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç Webmin/Usermin À¥ ÀÎÅÍÆäÀ̽º´Â miniserv.pl Perl À¥ ¼¹ö¿¡ ÀÖ´Â µð·ºÅ丮 Ž»ö Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. WebminÀº Unix¿Í Linux ¿î¿µÃ¼Á¦µéÀ» À§ÇÑ À¥ ±â¹ÝÀÇ ½Ã½ºÅÛ °ü¸® ÅøÀÌ´Ù. ±×¸®°í UserminÀº ½Ã½ºÅÛ °ü¸®Àڵ麸´Ù´Â ÀÏ¹Ý »ç¿ëÀڵ鿡 ÀÇÇÑ »ç¿ëÀ» À§ÇØ °í¾ÈµÈ WebminÀÇ Ãà¼Ò ¹öÀüÀÌ´Ù. Webmin 1.296 ÀÌÀüÀÇ ¹öÀüµé°ú Usermin 1.226 ÀÌÀüÀÇ ¹öÀüµéÀº NULL (%00) ¹®ÀÚ¸¦ °¡Áø URL¿¡ ´ëÇÑ ºÎÀûÀýÇÑ Ã³¸®·Î ÀÎÇÏ¿© ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ Cross-Site Scripting (XSS)À» ¼öÇàÇϰųª, CGI ÇÁ·Î±×·¥ ¼Ò½º Äڵ带 ÀÐ¾î ³»°Å³ª, µð·ºÅ丮µéÀ» ¸ñ·ÏÈÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.webmin.com/security.html http://secunia.com/advisories/21690/
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Usermin Project, Usermin 1.226 ÀÌÀüÀÇ ¹öÀüµé Webmin Project, Webmin 1.296 ÀÌÀüÀÇ ¹öÀüµé Unix Any version Linux Any version |
ÇØ°áÃ¥ |
Webmin À¥ »çÀÌÆ®ÀÎ http://www.webmin.com/webmin/ ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â Webmin / UserminÀÇ °¡Àå ÃֽŠ¹öÀü(Webmin 1.296 / Usermin 1.226 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2006-4542 (CVE) |
°ü·Ã URL |
19820 (SecurityFocus) |
°ü·Ã URL |
28699,28701 (ISS) |
|