Ãë¾àÁ¡ID |
22320 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç Blazix À¥ ¼¹ö´Â JSP ¼Ò½º ³ëÃâ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Blazix´Â Java·Î Á¦ÀÛµÈ ¹«·á·Î »ç¿ë °¡´ÉÇÑ °ø°³ ¼Ò½º À¥ ¼¹öÀÌ´Ù. ÀÌ ¼¹ö´Â Linux, Unix ±×¸®°í Microsoft Windows ¿î¿µÃ¼Á¦ µé¿¡¼ »ç¿ë °¡´ÉÇÏ´Ù. Blazix 1.2.2 ÀÌÀüÀÇ ¹öÀüµéÀº "+" ȤÀº "\" (backslash) ¹®ÀÚ·Î ³¡³ª´Â HTTP ¿äûÀ» ÅëÇÏ¿© ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ JSP ½ºÅ©¸³Æ®µéÀÇ ¼Ò½º Äڵ带 Àаųª Á¦ÇÑµÈ À¥ µð·ºÅ丮 µéÀ» ¸®½ºÆÃ ÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. ÀÌ Á¤º¸´Â °ø°ÝÀÚ°¡ ¿µÇâÀ» ¹Þ´Â ¼¹ö¿¡ ´ëÇØ Á» ´õ Á¤¹ÐÇÑ °ø°ÝµéÀ» °³½ÃÇϴµ¥ µµ¿òÀ» ÁØ´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/bugtraq/2002-08/0259.html http://www.securiteam.com/securitynews/5NP0M1F80G.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Desiderata Software, Blazix 1.2.2 ÀÌÀüÀÇ ¹öÀüµé Linux Any version Unix Any version Microsoft Windows Any version |
ÇØ°áÃ¥ |
BlazixÀÇ À¥ »çÀÌÆ®ÀÎ http://www.blazix.com/download.jsp ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â Blazix ¼¹öÀÇ °¡Àå ÃֽйöÀü(1.2.2 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2002-1451 (CVE) |
°ü·Ã URL |
5566 (SecurityFocus) |
°ü·Ã URL |
9952 (ISS) |
|