English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22236
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Servlet
»ó¼¼¼³¸í Resin 'view_source.jsp' »ùÇà ½ºÅ©¸³Æ®´Â µð·ºÅ丮 Ž»ö Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Caucho Technology¿¡ ÀÇÇØ °³¹ßµÈ ResinÀº Java¿Í JavaScript¸¦ Áö¿øÇÏ´Â ¼­ºí¸´(servlet) ¹× Java Server Pages (JSP) ¿£ÁøÀÌ´Ù. Microsoft Windows Ç÷§ÆûÀÇ Resin ¹öÀü 2.1.2¿¡ ÀÖ´Â 'view_source.jsp' »ùÇà ½ºÅ©¸³Æ®´Â ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ À¥ ¼­¹ö »ó¿¡ ÀÖ´Â ÀÓÀÇÀÇ ÆÄÀϵéÀÇ ³»¿ëÀ» º¼ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
'view_source.jsp' ½ºÅ©¸³Æ®´Â '/../' ½ÃÄö½ºµéÀ» ÅëÇÑ µð·ºÅ丮 Ž»öÀº ¹æÁöÇÑ´Ù. ±×·¯³ª °ø°ÝÀÚ°¡ '\..\' ½ÃÄö½ºµéÀ» ÅëÇØ µð·ºÅ丮 Ž»ö ½ÃµµÇÏ¸é ¼º°øÇÑ´Ù. ÀÌ´Â °ø°ÝÀÚ°¡ À¥ ¼­¹ö¿¡ ÀÇÇØ ÀÐÇôÁö´Â Ãë¾àÇÑ ½Ã½ºÅÛ »óÀÇ ¾î¶°ÇÑ ÆÄÀϵ鵵 ÀÐ¾î °¥ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2002-06/0168.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Resin 2.1.2
Microsoft Windows Any version
ÇØ°áÃ¥ ´ÙÀ½ Caucho Technology À¥ »çÀÌÆ®¿¡¼­ ResinÀÇ °¡Àå ÃֽйöÀü(2.1.11 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://caucho.com/products/resin/download

-- ȤÀº --

»ùÇà ½ºÅ©¸³Æ®µéÀÌ ÇÊ¿äÇÏÁö ¾Ê´Ù¸é "Examples" Æú´õ¸¦ »èÁ¦ÇÑ´Ù.
°ü·Ã URL CVE-2002-1987 (CVE)
°ü·Ã URL 5031 (SecurityFocus)
°ü·Ã URL 9351 (ISS)