Ãë¾àÁ¡ID |
21235 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç IIS À¥¼¹ö´Â FrontPage CGI /_vti_bin/shtml.dllÀ» ÅëÇÑ Cross-Site-Scripting °ø°Ý¿¡ Ãë¾àÇÏ´Ù. IIS 4.0°ú 5.0¿¡ ÀÖ´Â ÀÌ Ãë¾àÁ¡Àº ¾ÇÀÇÀûÀÎ À¥ »çÀÌÆ® ¿î¿µÀÚ°¡ ½Å·ÚÇÒ ¸¸ÇÑ »çÀÌÆ®ÀÇ ¾î¶² ¸µÅ©¿¡ ½ºÅ©¸³Æ®µéÀ» Æ÷ÇÔ½ÃÄÑ ³õÀ» ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. À̴ Ŭ¶óÀÌ¾ðÆ®¿¡ ¾î¶² ¿¡·¯ ¸Þ½ÃÁöµµ ¾øÀÌ ¸®ÅϵȴÙ. Á¤»óÀûÀÎ »ç¿ëÀÚµéÀº À¥ ÆäÀÌÁöµé¿¡ ÀÖ´Â ½Å·ÚÇÏÁö ¸øÇÏ´Â ¸µÅ©µéÀ» µû¶ó°¥ ¶§ °ø°ÝÀÚ¿¡ ÀÇÇØ ÀÛ¼ºµÈ ½ºÅ©¸³Æ®¸¦ ÀǽÄÇÏÁö ¸øÇÑ Ã¤ ½ÇÇàÇÒ ¼ö ÀÖ´Ù. »ç¿ëÀÚµéÀº ¶ÇÇÑ ´Ù¸¥ »ç¿ëÀڵ鿡 ÀÇÇØ Á¦°øµÇ´Â ³»¿ëµé¿¡ ±Ù°ÅÇÑ µ¿Àû »ý¼º ÆäÀÌÁöµéÀ» º¼ ¶§ ¾ÇÀÇÀûÀÎ ½ºÅ©¸³Æ®µéÀ» Àڱ⵵ ¸ð¸£°Ô ½ÇÇàÇÒ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.microsoft.com/technet/security/bulletin/ms00-060.asp http://www.cert.org/advisories/CA-2000-02.html http://archives.neohapsis.com/archives/bugtraq/2000-08/0244.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Microsoft IIS 4.0 Microsoft IIS 5.0 Microsoft Personal Web Server 4.0 Microsoft Windows Any version |
ÇØ°áÃ¥ |
´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS00-060À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://www.microsoft.com/technet/security/bulletin/ms00-060.asp |
°ü·Ã URL |
CVE-2000-0746,CVE-2000-1104 (CVE) |
°ü·Ã URL |
1594,1595 (SecurityFocus) |
°ü·Ã URL |
5156 (ISS) |
|