Ãë¾àÁ¡ID |
21281 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
Man Page Lookup ÇÁ·Î±×·¥Àº ¿ø°ÝÁö °ø°ÝÀÚµéÀÌ À¥ ¼¹ö »óÀÇ ÀÓÀÇÀÇ ÆÄÀÏÀ» ÀÐÀ» ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù. Man Page Lookup Àº Linux¿Í Unix ±â¹Ý ¿î¿µÃ¼Á¦ »ó¿¡¼ À¥ ºê¶ó¿ìÀú¸¦ ÅëÇØ man ÆäÀÌÁöµéÀ» º¼ ¼ö ÀÖµµ·Ï Áö¿øÇÏ´Â ÇÁ·Î±×·¥ÀÌ´Ù. ÀÌ ÆÄÀÏ ³ëÃâ Ãë¾àÁ¡Àº Man Page Lookup ÇÁ·Î±×·¥ »ó¿¡ Á¸ÀçÇÏ´Â class.manpagelookup.php ½ºÅ©¸³Æ® ¾ÈÀÇ buildManPage() ÇÔ¼ö¿¡¼ »ç¿ëÀÚ¿¡ ÀÇÇØ ÀԷµǴ command ÆÄ¶ó¹ÌÅÍ($cmd º¯¼ö)°¡ ¿Ã¹Ù¸£°Ô ÇÊÅ͸µµÇÁö ¸øÇÏ¿© ¹ß»ýÇÑ´Ù. ´ÙÀ½°ú °°ÀÌ index.php ½ºÅ©¸³Æ®ÀÇ command ÆÄ¶ó¹ÌÅ͸¦ ÀÌ¿ëÇÏ¿© ¿ø°ÝÁö °ø°ÝÀÚµéÀº ´ë»ó ½Ã½ºÅÛ »óÀÇ Àб⠰¡´ÉÇÑ ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐ¾î ³¾ ¼ö ÀÖ´Ù:
http://[target]/manpage/index.php?command=/etc/passwd
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/bugtraq/2004-01/0079.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Andy's PHP Projects Man Page Lookup prior to 1/2/2004 Linux Any version Unix Any version |
ÇØ°áÃ¥ |
´ÙÀ½ÀÇ Andy's PHP Projects À¥ ÆäÀÌÁö¸¦ ÂüÁ¶ÇÏ¿© 2004³â 1¿ù 2ÀÏ ÀÌÈÄ¿¡ °Ô½ÃµÈ Man Page LookupÀÇ °¡Àå ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://php.amnuts.com/index.php?do=view&id=1 |
°ü·Ã URL |
CVE-2004-0071 (CVE) |
°ü·Ã URL |
9395 (SecurityFocus) |
°ü·Ã URL |
14203 (ISS) |
|