Ãë¾àÁ¡ID |
21289 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
Servlet |
»ó¼¼¼³¸í |
Netware 6.0¿¡ ¹èÆ÷µÈ ÇØ´ç Apache Tomcat ¼¹ö´Â µð·ºÅ丮 Ž»ö Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Apache TomcatÀº JSP(JavaServer Page)µé°ú Java ¼ºí¸´(servlet)µéÀ» Áö¿øÇϱâ À§ÇÏ¿© Apache HTTP ¼¹ö¿Í ÇÔ²² »ç¿ëµÇ´Â Java ¾îÇø®ÄÉÀÌ¼Ç ¼¹öÀÌ´Ù. Netware 6.0¿¡ ¹èÆ÷µÈ Apache Tomcat ¼¹ö¿¡ ÀÖ´Â '/examples/jsp/source.jsp' ¿¹Á¦ ½ºÅ©¸³Æ®´Â ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ À¥ ¼¹ö »ó¿¡ ÀÖ´Â ÀÓÀÇÀÇ ÆÄÀϵéÀÇ ³»¿ëÀ» º¼ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. 'source.jsp' ½ºÅ©¸³Æ®´Â '/../' ½ÃÄö½ºµéÀ» ÅëÇÑ µð·ºÅ丮 Ž»öÀ» Â÷´ÜÇÑ´Ù. ±×·¯³ª Unicode ¹®ÀÚµéÀ» °¡Áø '/%2e%2e/' ½ÃÄö½ºµéÀ» ÅëÇÑ µð·ºÅ丮 Ž»öÀ» ½ÃµµÇÏ´Â °ø°ÝÀÚ´Â ¼º°øÇÑ´Ù. ÀÌ´Â °ø°ÝÀÚ°¡ À¥ ¼¹ö¿¡ ÀÇÇØ ÀÐÀ» ¼ö ÀÖ´Â Ãë¾àÇÑ ½Ã½ºÅÛ »óÀÇ ¾î¶² ÆÄÀϵ鿡 ´ëÇÑ ¿äûÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ÀÌ Ãë¾àÁ¡À» µµ¿ëÇϱâ À§ÇÏ¿© ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¾Ë·ÁÁø ÆÄÀÏ¿¡ ´ëÇØ "dot dot" ½ÃÄö½º (/%2e%2e/)¸¦ Æ÷ÇÔÇÑ "source.jsp" ¿äûÀ» º¸³½´Ù. ÀÌ´Â °ø°ÝÀÚ°¡ AUTOEXEC.NCF¿¡ À§Ä¡ÇÑ RCONSOLE ÆÐ½º¿öµå¿Í °°Àº Netware ¼¹ö¿¡¼ Áß¿äÇÑ Á¤º¸¸¦ ¾ò¾î ¿Ã ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
http://[targetserver]/examples/jsp/source.jsp?%2e%2e/%2e%2e/%2e%2e/%2e%2e/system/autoexec.ncf
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Apache Software Foundation Tomcat Any version Netware 6.0 |
ÇØ°áÃ¥ |
¿µÇâÀ» ¹Þ´Â À¥ ¼¹ö·ÎºÎÅÍ "/examples/" °¡»ó µð·ºÅ丮¿¡ À§Ä¡ÇØ ÀÖ´Â µðÆúÆ® ¿¹Á¦ ÆÄÀϵéÀ» »èÁ¦ÇÏ¿©¾ß ÇÑ´Ù. ¶ÇÇÑ RCONSOLE ÆÐ½º¿öµå°¡ ¾ÏȣȵǾî ÀÖ´ÂÁö¿Í ÄÜ¼Ö ¾×¼¼½º ½Ã ÆÐ½º¿öµå·Î º¸È£µÈ ȸ麸ȣ±â¸¦ »ç¿ëÇϰí ÀÖ´ÂÁö¸¦ È®½ÇÈ÷ ÇØ µÎ¾î¾ß ÇÑ´Ù. |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|