Ãë¾àÁ¡ID |
23067 |
À§Çèµµ |
30 |
Æ÷Æ® |
6680 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
LDAP |
»ó¼¼¼³¸í |
ÇØ´ç SurgeLDAP ¼¹ö¿¡´Â Cross-Site Scripting Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. SurgeLDAPÀº Microsoft Windows ¿Í Linux °è¿ÀÇ ¿î¿µÃ¼Á¦ »ó¿¡¼ µ¿ÀÛÇÏ´Â Lightweight Directory Access Protocol (LDAP) v3 ¼¹öÀÌ´Ù. SurgeLDAP ¼¹öÀÇ v1.0d ¿Í ±× ÀÌÀü ¹öÀü¿¡´Â "user.cgi"¿Í °°Àº CGI ½ºÅ©¸³Æ® »ó¿¡¼ »ç¿ëÀÚ ÀÔ·ÂÀÌ ÀûÀýÈ÷ ÇÊÅ͸µµÇÁö ¸øÇÔÀ¸·Î ÀÎÇÏ¿© Cross-Site Scripting Ãë¾àÁ¡ÀÌ ¹ß»ýÇÒ ¼ö ÀÖ´Ù. °ø°ÝÀÚµéÀº ´ÙÀ½°ú °°ÀÌ ¾ÇÀÇÀûÀÎ HTML ¶Ç´Â Java Script¸¦ »ðÀÔÇÑ HTTP ¿äûÀ» ¼¹ö¿¡ Àü´ÞÇÔÀ¸·Î½á, ÇØ´ç ¼¹öÀÇ ±ÇÇÑÀ¸·Î ´ë»ó »ç¿ëÀÚÀÇ À¥ ºê¶ó¿ìÀú »ó¿¡¼ ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡Àº ´ë»ó ½Ã½ºÅÛÀÇ ÄíŰ(cookie) ±â¹Ý ÀÎÁõÁ¤º¸µéÀ» ÈÉÄ¡±â À§ÇØ ÀÌ¿ëµÉ ¼ö ÀÖ´Ù.
http://[host]:6680/user.cgi?cmd=<script>alert('XSS')</script>&utoken=
* Âü°í »çÀÌÆ®: http://www.securiteam.com/windowsntfocus/5RP0I0UAUI.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: NetWin surgeLDAP version 1.0d ¿Í ±× ÀÌÀü ¹öÀü. Linux Any version Windows Any version |
ÇØ°áÃ¥ |
http://www.softpicks.net/software/Internet/Email/SurgeLDAP-Server-8756.htm ·ÎºÎÅÍ SurgeLDAP ¼¹öÀÇ ¹öÀü 1.0e ÀÌ»ó ¶Ç´Â °¡Àå ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. SurgeLDAP ¼¹öÀÇ °¡Àå ÃֽйöÀüÀÎ v1.0g °¡ 2003³â 12¿ù¿¡ ¸±¸®Áî µÇ¾ú´Ù. |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
8407 (SecurityFocus) |
°ü·Ã URL |
12901 (ISS) |
|