|
커피향이 나는 *NIX
커피닉스
시스템/네트웍/보안을 다루는 곳
|
|
|
|
| 이전 주제 보기 :: 다음 주제 보기 |
| 글쓴이 |
메시지 |
truefeel 카페 관리자
가입: 2003년 7월 24일 올린 글: 1277 위치: 대한민국
|
올려짐: 2006.2.24 금, 4:39 pm 주제: SquirrelMail XSS & IMAP 취약성 |
|
|
대표적인 PHP기반 웹메일 프로그램인 SquirrelMail에 몇가지 취약성이 발견되었습니다.
1.4.5 버전까지 이문제들은 존재합니다. 23일 1.4.6이 발표되었으니 업그레이드 하세요.
* webmail.php에서 right_frame 파라미터를 통한 XSS(Cross-Site Scripting) 취약성
http://www.squirrelmail.org/security/issue/2006-02-01
* MagicHTML 에 XSS 취약성 (IE 브라우저만)
MagicHTML 필터가 스타일시트 내의 주석을 정확하게 무시하지 못해 메일을 읽는 사용자의 개인정보를 얻어낼 수 있는 문제가 있습니다.
http://www.squirrelmail.org/security/issue/2006-02-10
* sqimap_mailbox_select의 mailbox 파라미터에 IMAP injection 취약성
http://www.squirrelmail.org/security/issue/2006-02-15
관련정보 : http://secunia.com/advisories/18985/
| 코드: |
Secunia Advisory: SA18985 Print Advisory
Release Date: 2006-02-22
Critical: Less critical
Impact: Cross Site Scripting
Manipulation of data
Where: From remote
Solution Status: Vendor Patch
Software: SquirrelMail 1.x
Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.
CVE reference: CVE-2006-0188
CVE-2006-0195
CVE-2006-0377
Description:
Some vulnerabilities have been reported in SquirrelMail, which can be exploited by malicious users to manipulate certain information and by malicious people to conduct cross-site scripting attacks.
... 생략 ...
|
|
|
| 위로 |
|
 |
|
|
새로운 주제를 올릴 수 있습니다 답글을 올릴 수 있습니다 주제를 수정할 수 없습니다 올린 글을 삭제할 수 없습니다 투표를 할 수 없습니다
|
Powered by phpBB © 2001, 2005 phpBB Group
|