Ãë¾àÁ¡ID |
21298 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç osCommerce´Â file_manager.php ½ºÅ©¸³Æ®¸¦ ÅëÇÑ µð·ºÅ丮 Ž»ö Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. osCommerce´Â °ø°³ ¼Ò½º ´Üü¿¡ ÀÇÇØ °³¹ßÀÌ ÁøÇàµÇ¾î ¿Â ¿Â¶óÀÎ ¼îÇÎÀ» À§ÇÑ e-commerce ¼Ö·ç¼ÇÀÌ´Ù. osCommerce 2.2ms1 ÀÌÇÏ ¹öÀüµéÀº »ç¿ëÀÚ°¡ °ø±ÞÇÑ ÀԷ°ªÀ» ÀûÀýÈ÷ ÇÊÅ͸µÇÏÁö ¸øÇÏ´Â °áÇÔÀ¸·Î ÀÎÇØ, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¿µÇâÀ» ¹Þ´Â À¥ ¼¹ö»óÀÇ ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐ¾î ³¾ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ´ÙÀ½°ú °°ÀÌ "dot dot(..)" ½ÃÄö½ºµéÀ» ÅëÇØ Ãë¾àÇÑ À¥ ¼¹ö»óÀÇ Àб⠰¡´ÉÇÑ ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐ¾î ³¾ ¼ö ÀÖ´Ù: http://[vulnerable.host]/oscommerce/admin/file_manager.php?action=download&filename=../../../../../../../../etc/passwd
* Âü°í »çÀÌÆ®: http://www.securiteam.com/unixfocus/5GP0D2KCUQ.html http://archives.neohapsis.com/archives/bugtraq/2004-05/0162.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: osCommerce Any version Microsoft Windows Any version Linux Any version Unix Any version |
ÇØ°áÃ¥ |
osCommerce ´Ù¿î·Îµå À¥ »çÀÌÆ®ÀÎ http://www.oscommerce.com/solutions/downloads ¿¡¼ »õ·Î¿î ¼öÁ¤µÈ ¹öÀüÀÌ ´Ù¿î·Îµå °¡´ÉÇÒ ¶§ osCommerce °¡Àå ÃֽйöÀüÀ» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2004-2021 (CVE) |
°ü·Ã URL |
10364 (SecurityFocus) |
°ü·Ã URL |
16174 (ISS) |
|