English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21281
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í Man Page Lookup ÇÁ·Î±×·¥Àº ¿ø°ÝÁö °ø°ÝÀÚµéÀÌ À¥ ¼­¹ö »óÀÇ ÀÓÀÇÀÇ ÆÄÀÏÀ» ÀÐÀ» ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù. Man Page Lookup Àº Linux¿Í Unix ±â¹Ý ¿î¿µÃ¼Á¦ »ó¿¡¼­ À¥ ºê¶ó¿ìÀú¸¦ ÅëÇØ man ÆäÀÌÁöµéÀ» º¼ ¼ö ÀÖµµ·Ï Áö¿øÇÏ´Â ÇÁ·Î±×·¥ÀÌ´Ù. ÀÌ ÆÄÀÏ ³ëÃâ Ãë¾àÁ¡Àº Man Page Lookup ÇÁ·Î±×·¥ »ó¿¡ Á¸ÀçÇÏ´Â class.manpagelookup.php ½ºÅ©¸³Æ® ¾ÈÀÇ buildManPage() ÇÔ¼ö¿¡¼­ »ç¿ëÀÚ¿¡ ÀÇÇØ ÀԷµǴ command ÆÄ¶ó¹ÌÅÍ($cmd º¯¼ö)°¡ ¿Ã¹Ù¸£°Ô ÇÊÅ͸µµÇÁö ¸øÇÏ¿© ¹ß»ýÇÑ´Ù. ´ÙÀ½°ú °°ÀÌ index.php ½ºÅ©¸³Æ®ÀÇ command ÆÄ¶ó¹ÌÅ͸¦ ÀÌ¿ëÇÏ¿© ¿ø°ÝÁö °ø°ÝÀÚµéÀº ´ë»ó ½Ã½ºÅÛ »óÀÇ Àб⠰¡´ÉÇÑ ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐ¾î ³¾ ¼ö ÀÖ´Ù:

http://[target]/manpage/index.php?command=/etc/passwd

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2004-01/0079.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Andy's PHP Projects Man Page Lookup prior to 1/2/2004
Linux Any version
Unix Any version
ÇØ°áÃ¥ ´ÙÀ½ÀÇ Andy's PHP Projects À¥ ÆäÀÌÁö¸¦ ÂüÁ¶ÇÏ¿© 2004³â 1¿ù 2ÀÏ ÀÌÈÄ¿¡ °Ô½ÃµÈ Man Page LookupÀÇ °¡Àå ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://php.amnuts.com/index.php?do=view&id=1
°ü·Ã URL CVE-2004-0071 (CVE)
°ü·Ã URL 9395 (SecurityFocus)
°ü·Ã URL 14203 (ISS)