| 
   
            
 	            | Ãë¾àÁ¡ID | 29108 |   
 	            | À§Çèµµ | 40 |  
 	            | Æ÷Æ® | 80 |  	
 	            | ÇÁ·ÎÅäÄÝ | TCP |  	
 	            | ºÐ·ù | WWW |  	
 	            | »ó¼¼¼³¸í | SonicWALL SOHO/10ÀÇ ÇØ´ç À¥ ÀÎÅÍÆäÀ̽º´Â ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. SonicWALL SOHO/10Àº ¹æÈº®, VPN ÄÁÅÙÆ® ÇÊÅ͸µ µîÀ» Æ÷ÇÔÇÑ ¿©·¯ ¼³ºñµéÀ» °®Ãá ÀÎÅÍ³Ý º¸¾È ¾îÇöóÀ̾ð½º(Appliance)ÀÌ´Ù. SonicWALL SOHO/10 Æß¿þ¾î ¹öÀü 5.1.7.0Àº µÎ°¡Áö Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ Cross-Site Scripting ±×¸®°í ½ºÅ©¸³Æ® ÁÖÀÔ °ø°ÝµéÀ» ¼öÇàÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù. 
 1) SonicWALL SOHO/10¿¡ ÀÖ´Â Cross-Site Scripting Ãë¾àÁ¡Àº Ãë¾àÇÑ »çÀÌÆ®ÀÇ È¯°æ ÇÏ¿¡¼ »ç¿ëÀÚ ºê¶ó¿ìÀú ¼¼¼ÇÀ¸·Î ÀÓÀÇÀÇ HTML°ú ½ºÅ©¸³Æ® Äڵ带 ½ÇÇàÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.
 2) SonicWALL SOHO/10¿¡ ÀÖ´Â ÀÓÀÇÀÇ ÄÚµå ÁÖÀÔ Ãë¾àÁ¡Àº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¾ÇÀÇÀûÀÎ Äڵ带 Æ÷ÇÔÇÑ »ç¿ëÀÚ¸íÀ» ÀåºñÀÇ ·Î±×ÀÎ ÆäÀÌÁö·Î º¸³¾ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ÀÌ´Â Àåºñ°¡ »ç¿ëÀÚ¸íÀ» ·Î±×ÆÄÀÏ¿¡ ÀúÀåÇÏ°Ô ÇÏ´Â ¿øÀÎÀÌ µÈ´Ù. ±×¸®°í ³ª¼ °ü¸®ÀÚ°¡ ±× ·Î±×ÆÄÀÏÀ» º¸·Á°í ÇÒ ¶§ ±× ¾ÇÀÇÀûÀÎ Äڵ尡 °ü¸®ÀÚÀÇ ºê¶ó¿ìÀú¿¡ ÀÇÇØ ½ÇÇàµÇ°Ô µÈ´Ù.
 
 * Âü°í »çÀÌÆ®:
 http://www.securitytracker.com/alerts/2005/Apr/1013638.html
 http://secunia.com/advisories/14823/
 http://archives.neohapsis.com/archives/bugtraq/2005-04/0041.html
 http://www.oliverkarow.de/research/sonicwall.txt
 
 * ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
 SonicWALL SOHO/10 Æß¿þ¾î ¹öÀü 5.1.7.0
 Microsoft Windows Any version
 |  	
 	            | ÇØ°áÃ¥ | 2014³â 6¿ù ÇöÀç ¾÷±×·¹À̵峪 ÆÐÄ¡´Â ³ª¿Í ÀÖÁö ¾Ê´Ù. |  	
 	            | °ü·Ã URL | CVE-2005-1006 (CVE) |  	
 	            | °ü·Ã URL | 12984 (SecurityFocus) |  
 	            | °ü·Ã URL | 19958,19960 (ISS) |  |