Ãë¾àÁ¡ID |
21257 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
AspUploadÀÇ À§ÇèÇÑ ¿¹Á¦ ½ºÅ©¸³Æ®µéÀÌ ÇØ´ç À¥¼¹ö¿¡ Á¸ÀçÇÑ´Ù. AspUpload´Â »ç¿ëÀÚµéÀÌ À¥ ºê¶ó¿ìÀú¸¦ ÅëÇØ ÆÄÀϵéÀ» ASP ÇÁ·Î±×·¥À¸·Î ¾÷·Îµå(upload) ÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁÖ´Â Active Server ÄÄÆ÷³ÍÆ®ÀÌ´Ù. AspUpload ¹öÀü 2.1°ú 3.0Àº ¼³Ä¡½Ã µðÆúÆ®·Î ¿¹Á¦ ½ºÅ©¸³Æ®µéÀ» »ý¼ºÇÑ´Ù. 'UploadScript11.asp' ȤÀº 'DirectoryListing.asp'¿Í °°Àº ¿¹Á¦ ½ºÅ©¸³Æ®µéÀº "dot dot (..)" ¹®ÀÚµéÀ» ÀûÀýÇÏ°Ô °É·¯ ³»Áö ¸øÇÏ´Â °áÇÔÀ» °¡Áö°í ÀÖ¾î ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ À¥ ¼¹ö »ó¿¡ ÀÖ´Â µð·ºÅ丮µéÀ» Ž»öÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡µé µµ¿ëÇÏ¿© À¥ ¼¹ö°¡ Á¸ÀçÇÏ´Â µå¶óÀÌºê »ó¿¡ À§Ä¡ÇÑ ÀÓÀÇÀÇ ÆÄÀϵéÀ» ´Ù¿î·ÎµåÇϰųª ¾÷·ÎµåÇÒ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/bugtraq/2001-11/0292.html http://www.securiteam.com/windowsntfocus/5DP070U60M.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: ASPUpload ¹öÀü 2.1 ASPUpload ¹öÀü 3.0 Microsoft Windows Any version |
ÇØ°áÃ¥ |
ÇÊ¿äÇÏÁö ¾Ê´Ù¸é "C:\Program Files\Persits Software\AspUpload\Samples"¿¡ À§Ä¡ÇÑ ¿¹Á¦ ½ºÅ©¸³Æ®µéÀ» »èÁ¦ÇÑ´Ù.
-- ȤÀº --
´ÙÀ½ »çÀÌÆ®¸¦ ÅëÇØ AspUploadÀÇ °¡Àå ÃֽйöÀü (3.0 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ°í º¥´õ¿¡ ÀÇÇØ ±Ç°íµÇ´Â ¸ðµç ÆÐÄ¡µéÀ» Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://www.aspupload.com |
°ü·Ã URL |
CVE-2001-0938 (CVE) |
°ü·Ã URL |
3608 (SecurityFocus) |
°ü·Ã URL |
7628,7629 (ISS) |
|