Ãë¾àÁ¡ID |
22215 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç ColdFusion MX ¼¹ö´Â RDS ¼ºñ½º¸¦ ÅëÇÑ ´ÙÁßÀÇ Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ´Ù. ColdFusion RDS´Â °³¹ßÀÚµéÀÌ ¿ø°ÝÁö ÆÄÀϰú µ¥ÀÌÅÍ ¼Ò½ºµé, ±×¸®°í Debug CFML Äڵ带 ¾ÈÀüÇÏ°Ô ¾×¼¼½ºÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù. °³¹ßÀÚµéÀº ColdFusion Studio, Homesite+, ±×¸®°í Dreamweaver MX¸¦ ÅëÇØ RDS¸¦ »ç¿ëÇÏ¿© HTTP Á¢¼ÓÀ» ÀÌ¿ëÇÑ ¿ø°ÝÁö ColdFusion °³¹ß ¼¹ö¿¡ ÀÖ´Â ÆÄÀϵé°ú µ¥ÀÌÅͺ£À̽ºµéÀ» ¾×¼¼½ºÇÒ ¼ö ÀÖ´Ù. ÀûÀýÇÏ°Ô ¼³Á¤µÇ¾î ÀÖ´Ù¸é RDS´Â ¿ø°ÝÁö °³¹ßÀÚ¸¦ ÀÎÁõÇÒ ¼ö ÀÖ´Â ÆÐ½º¿öµå¸¦ ÇÊ¿ä·Î ÇÑ´Ù. ù¹øÂ° Ãë¾àÁ¡Àº ¿ø°ÝÁöÀÇ »ç¿ëÀÚ°¡ ColdFusion ¼¹ö¿¡ ÀÖ´Â ÀÓÀÇÀÇ ÆÄÀÏÀ» (Put ±×¸®°í Get) ¾×¼¼½ºÇÏ¿© Ãë¾àÇÑ À¥ »çÀÌÆ®ÀÇ ÀÚ¿øµéÀ» Àç¼³Á¤ÇÒ ¼ö ÀÖ´Ù´Â °ÍÀÌ´Ù. µÎ¹øÂ° Ãë¾àÁ¡Àº µðÆúÆ®·Î RDS´Â ÀÎÁõÀ» À§ÇÑ ÆÐ½º¿öµå¸¦ ÇÊ¿ä·Î ÇÏÁö ¾Ê´Â °Í(Null ÆÐ½º¿öµå)ÀÌ´Ù. ÀÌ ¶§¹®¿¡ RDS¿Í ȣȯÇÏ´Â °³¹ß ¾îÇø®ÄÉÀ̼ÇÀ» °¡Áø ÀÓÀÇÀÇ »ç¿ëÀÚ°¡ ÆÐ½º¿öµå ¾øÀÌ ÀÎÁõÀ» ¹Þ¾Æ RDS°¡ ÀÛµ¿ÇÏ´Â ColdFusion ¼¹ö¿¡ Á¢¼ÓÇÒ ¼ö ÀÖ´Ù´Â °ÍÀÌ´Ù. ¼¼¹øÂ° Ãë¾àÁ¡Àº RDS ÆÐ½º¿öµåÀÌ ¼³Á¤µÇ¾î ÀÖÀ» ¶§, ÆÐ½º¿öµå°¡ ¾ÏȣȵÇÁö ¾ÊÀº ÅØ½ºÆ®·Î Àü¼ÛµÇ¾î Áø´Ù´Â °ÍÀÌ´Ù.
* Âü°í »çÀÌÆ®: http://sec.angrypacket.com/advisories/0006_AP.CF-rds-dump.txt http://www.securitytracker.com/alerts/2003/Jul/1007124.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû Macromedia ColdFusion Server MX Professional Macromedia ColdFusion Server MX Enterprise Macromedia ColdFusion Server MX Developer Macromedia ColdFusion Server MX 6.0 Microsoft Windows Any version |
ÇØ°áÃ¥ |
2014³â 6¿ù ÇöÀç·Î½á´Â ÆÐÄ¡³ª ¾÷±×·¹À̵尡 ³ª¿ÍÀÖÁö ¾Ê´Ù. |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
8109,8110 (SecurityFocus) |
°ü·Ã URL |
12569 (ISS) |
|