Ãë¾àÁ¡ID |
21327 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç À¥ ¼¹ö »óÀÇ EasyWeb FileManager ¸ðµâÀº µð·ºÅ丮 Ž»ö Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. EasyWeb FileManager ¸ðµâÀº PostNuke »ó¿¡¼ »çÀÌÆ® °ü¸®ÀÚ¿¡ ÀÇÇØ ÇÒ´çµÈ µð·ºÅ丮 ¾ÈÀÇ ÆÄÀÏ ¹× µð·ºÅ丮µéÀ» °ü¸®Çϱâ À§ÇØ ¼³°èµÈ ¸ðµâÀÌ´Ù. EasyWeb FileManager 1.0 RC-1Àº »ç¿ëÀÚ ÀÔ·Â µ¥ÀÌÅÍ¿¡ ´ëÇÑ ºÒÃæºÐÇÑ ÇÊÅ͸µÀ¸·Î ÀÎÇÏ¿©, ´ë»ó ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ ÆÄÀϵéÀ» ¿ø°ÝÁö °ø°ÝÀÚµéÀÌ º¼ ¼ö ÀÖµµ·Ï Çã¿ëÇÒ ¼ö ÀÖ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº ´ÙÀ½°ú °°ÀÌ 'pathext', 'view' º¯¼ö¿¡ Àß Á¶ÀÛµÈ °ªÀ» Æ÷ÇÔÇÑ ¿äûÀ» 'ew_filemanager' ½ºÅ©¸³Æ®¿¡ Àü´ÞÇÏ´Â ¹æ¹ýÀ¸·Î, ´ë»ó À¥ ¼ºñ½ºÀÇ ±ÇÇÑÀ¸·Î ¿ø°ÝÁö ½Ã½ºÅÛ »óÀÇ ÆÄÀϵéÀ» º¼ ¼ö ÀÖ´Ù:
/index.php?module=ew_filemanager&type=admin&func=manager&pathext=../../../etc /index.php?module=ew_filemanager&type=admin&func=manager&pathext=../../../etc/&view=passwd
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§Çؼ ½ÇÁ¦ Å×½ºÆ®¸¦ ¼öÇàÇÏÁö ¾ÊÀ¸¸ç ´ÜÁö À¥ ¼¹ö »ó¿¡¼ EasyWeb FileManager ¸ðµâÀÇ °¡µ¿¿©ºÎ ¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼, °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.cirt.net/EasyWeb+FileManager+Directory+Traversal http://www.securitytracker.com/alerts/2004/Jul/1010768.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: EasyWeb EasyWeb 1.0 RC-1 Linux Any version Unix Any version Microsoft Windows Any version |
ÇØ°áÃ¥ |
2014³â 6¿ù ÇöÀç ¾÷±×·¹À̵峪 ÆÐÄ¡´Â ³ª¿Í ÀÖÁö ¾Ê´Ù. Ãë¾àÁ¡¿¡ ´ëÇØ Á¦Ç°ÀÇ Á¦Á¶»ç¿¡ ¹®ÀÇÇÑ´Ù. |
°ü·Ã URL |
CVE-2004-2047 (CVE) |
°ü·Ã URL |
10792 (SecurityFocus) |
°ü·Ã URL |
16806 (ISS) |
|