Ãë¾àÁ¡ID |
21291 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
Servlet |
»ó¼¼¼³¸í |
ÇØ´ç Novell GroupWise ¼¹ö¿¡ ÀÖ´Â WebAcc ServletÀº µð·ºÅ丮 Ž»ö Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Novell GroupWise´Â Ç÷§Æû°£ Çùµ¿ÀÛ¾÷ ¹× ¸Þ¼¼Â¡ ½Ã½ºÅÛÀÌ´Ù. Novell GroupWise ¹öÀü 5.5¿Í 6¿¡ ÀÖ´Â /servlet/webacc ¼ºí¸´Àº »ç¿ëÀÚ Á¦°ø "User.html" ÀμöÀÇ ºÎÀûÀýÇÑ °ËÁõÀ¸·Î ÀÎÇÏ¿© ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ÀÓÀÇÀÇ À¥ ¼¹ö ÆÄÀÏÀÇ ³»¿ëÀ» º¼ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ÀÌ Ãë¾àÁ¡À» µµ¿ëÇϱâ À§ÇØ ¿ø°ÝÁö °ø°ÝÀÚµéÀº ´ÙÀ½°ú °°ÀÌ "dot dot" ½ÃÄö½º(/../)¿Í Àß ¾Ë·ÁÁø ÆÄÀÏ¿¡ ³Î ¹ÙÀÌÆ®(%00)¸¦ µ¡ºÙ¿© "/servlet/webacc" ¿äûÀ» ¼¹ö¿¡ Àü´ÞÇÑ´Ù.
http://[targetserver]//servlet/webacc?User.html=../../../../../../../../../../boot.ini
À§ÀÇ ¿äûÀ» ÅëÇØ °ø°ÝÀÚ´Â ¼¹ö ³»ÀÇ ¿äûÇÑ ÆÄÀÏÀ» ÀÐÀ» ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.kb.cert.org/vuls/id/341539 http://www.securiteam.com/securitynews/6S00N0K2UM.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Novell GroupWise 5.5 Enhancement Pack Novell GroupWise 6.0 |
ÇØ°áÃ¥ |
´ÙÀ½ NovellÀÇ ±â¼ú Á¤º¸ ¹®¼ 2960443À» Âü°íÇÏ¿© ÀÌ Ãë¾àÁ¡¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://www.novell.com/coolsolutions/gwmag/features/a_webaccess_security_gw.html |
°ü·Ã URL |
CVE-2001-1458 (CVE) |
°ü·Ã URL |
3436 (SecurityFocus) |
°ü·Ã URL |
7287 (ISS) |
|