English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21257
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í AspUploadÀÇ À§ÇèÇÑ ¿¹Á¦ ½ºÅ©¸³Æ®µéÀÌ ÇØ´ç À¥¼­¹ö¿¡ Á¸ÀçÇÑ´Ù.
AspUpload´Â »ç¿ëÀÚµéÀÌ À¥ ºê¶ó¿ìÀú¸¦ ÅëÇØ ÆÄÀϵéÀ» ASP ÇÁ·Î±×·¥À¸·Î ¾÷·Îµå(upload) ÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁÖ´Â Active Server ÄÄÆ÷³ÍÆ®ÀÌ´Ù. AspUpload ¹öÀü 2.1°ú 3.0Àº ¼³Ä¡½Ã µðÆúÆ®·Î ¿¹Á¦ ½ºÅ©¸³Æ®µéÀ» »ý¼ºÇÑ´Ù. 'UploadScript11.asp' ȤÀº 'DirectoryListing.asp'¿Í °°Àº ¿¹Á¦ ½ºÅ©¸³Æ®µéÀº "dot dot (..)" ¹®ÀÚµéÀ» ÀûÀýÇÏ°Ô °É·¯ ³»Áö ¸øÇÏ´Â °áÇÔÀ» °¡Áö°í ÀÖ¾î ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ À¥ ¼­¹ö »ó¿¡ ÀÖ´Â µð·ºÅ丮µéÀ» Ž»öÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡µé µµ¿ëÇÏ¿© À¥ ¼­¹ö°¡ Á¸ÀçÇÏ´Â µå¶óÀÌºê »ó¿¡ À§Ä¡ÇÑ ÀÓÀÇÀÇ ÆÄÀϵéÀ» ´Ù¿î·ÎµåÇϰųª ¾÷·ÎµåÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2001-11/0292.html
http://www.securiteam.com/windowsntfocus/5DP070U60M.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
ASPUpload ¹öÀü 2.1
ASPUpload ¹öÀü 3.0
Microsoft Windows Any version
ÇØ°áÃ¥ ÇÊ¿äÇÏÁö ¾Ê´Ù¸é "C:\Program Files\Persits Software\AspUpload\Samples"¿¡ À§Ä¡ÇÑ ¿¹Á¦ ½ºÅ©¸³Æ®µéÀ» »èÁ¦ÇÑ´Ù.

-- ȤÀº --

´ÙÀ½ »çÀÌÆ®¸¦ ÅëÇØ AspUploadÀÇ °¡Àå ÃֽйöÀü (3.0 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ°í º¥´õ¿¡ ÀÇÇØ ±Ç°íµÇ´Â ¸ðµç ÆÐÄ¡µéÀ» Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www.aspupload.com
°ü·Ã URL CVE-2001-0938 (CVE)
°ü·Ã URL 3608 (SecurityFocus)
°ü·Ã URL 7628,7629 (ISS)