English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21235
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç IIS À¥¼­¹ö´Â FrontPage CGI /_vti_bin/shtml.dllÀ» ÅëÇÑ Cross-Site-Scripting °ø°Ý¿¡ Ãë¾àÇÏ´Ù.
IIS 4.0°ú 5.0¿¡ ÀÖ´Â ÀÌ Ãë¾àÁ¡Àº ¾ÇÀÇÀûÀÎ À¥ »çÀÌÆ® ¿î¿µÀÚ°¡ ½Å·ÚÇÒ ¸¸ÇÑ »çÀÌÆ®ÀÇ ¾î¶² ¸µÅ©¿¡ ½ºÅ©¸³Æ®µéÀ» Æ÷ÇÔ½ÃÄÑ ³õÀ» ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. À̴ Ŭ¶óÀÌ¾ðÆ®¿¡ ¾î¶² ¿¡·¯ ¸Þ½ÃÁöµµ ¾øÀÌ ¸®ÅϵȴÙ.
Á¤»óÀûÀÎ »ç¿ëÀÚµéÀº À¥ ÆäÀÌÁöµé¿¡ ÀÖ´Â ½Å·ÚÇÏÁö ¸øÇÏ´Â ¸µÅ©µéÀ» µû¶ó°¥ ¶§ °ø°ÝÀÚ¿¡ ÀÇÇØ ÀÛ¼ºµÈ ½ºÅ©¸³Æ®¸¦ ÀǽÄÇÏÁö ¸øÇÑ Ã¤ ½ÇÇàÇÒ ¼ö ÀÖ´Ù. »ç¿ëÀÚµéÀº ¶ÇÇÑ ´Ù¸¥ »ç¿ëÀڵ鿡 ÀÇÇØ Á¦°øµÇ´Â ³»¿ëµé¿¡ ±Ù°ÅÇÑ µ¿Àû »ý¼º ÆäÀÌÁöµéÀ» º¼ ¶§ ¾ÇÀÇÀûÀÎ ½ºÅ©¸³Æ®µéÀ» Àڱ⵵ ¸ð¸£°Ô ½ÇÇàÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.microsoft.com/technet/security/bulletin/ms00-060.asp
http://www.cert.org/advisories/CA-2000-02.html
http://archives.neohapsis.com/archives/bugtraq/2000-08/0244.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft IIS 4.0
Microsoft IIS 5.0
Microsoft Personal Web Server 4.0
Microsoft Windows Any version
ÇØ°áÃ¥ ´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS00-060À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www.microsoft.com/technet/security/bulletin/ms00-060.asp
°ü·Ã URL CVE-2000-0746,CVE-2000-1104 (CVE)
°ü·Ã URL 1594,1595 (SecurityFocus)
°ü·Ã URL 5156 (ISS)