Ãë¾àÁ¡ID |
210090 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç À¥ ¼¹ö´Â ¾ÇÀÇÀûÀÎ JavaScript ÆÄÀϵé·ÎÀÇ ¸µÅ©µéÀ» Æ÷ÇÔÇÏ°í ÀÖ´Ù. ÀÌ´Â ´ë»ó À¥ »çÀÌÆ®°¡ ÀÎÅÍ³Ý ¿ú¿¡ °¨¿°µÇ¾úÀ½À» ÀǹÌÇÏ¸ç ¶ÇÇÑ À¥ »çÀÌÆ® ¹æ¹®°´µéµµ °¨¿°µÉ ¼ö ÀÖÀ½À» ÀǹÌÇÑ´Ù. ÀÌ´Â ¶ÇÇÑ °¨¿°µÈ À¥ »çÀÌÆ®°¡ SQL ÁÖÀÔ °ø°Ýµé¿¡ Ãë¾àÇÏ´Ù´Â °ÍÀ» ¸»ÇÑ´Ù. °ø°ÝÀÚµéÀº À¥ ¾îÇø®ÄÉÀÌ¼Ç °³¹ßÀ» À§ÇÑ º¸¾È¿¡ ÀÖ¾î¼ÀÇ ¸ð¹ü»ç·Ê(best practices)¸¦ µû¸£Áö ¾Ê´Â À¥ ÆäÀÌÁöµé¿¡ SQL ÁÖÀÔ Ãë¾àÁ¡µéÀ» ÀÌ¿ëÇÒ ¼ö ÀÖ´Â ÀÚµ¿ÈµÈ °ø°ÝÀ» °³¹ßÇØ ³õ¾Ò´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ´ë»ó À¥ »çÀÌÆ®¿¡ ¼öÁýµÈ À¥ ÆäÀÌÁöµé ³»¿¡¼ uc8010-dot-com ±×¸®°í ucmal-dot-com·ÎÀÇ ¸µÅ©µéÀÌ ¹ß°ßµÇ´ÂÁö¸¦ Á¡°ËÇÑ´Ù.
* Âü°í »çÀÌÆ®: http://isc.sans.org/diary.html?storyid=3810 http://secunia.com/advisories/28276/ http://www.kb.cert.org/vuls/id/871673 http://explabs.blogspot.com/2008/01/so-this-is-kind-of-interesting.html http://blogs.iis.net/bills/archive/2008/04/25/sql-injection-attacks-on-iis-web-servers.aspx
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: ¸ðµç HTTP ¼¹ö ¸ðµç ¹öÀü ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
°¨¿°µÈ À¥ »çÀÌÆ®¸¦ ¿ø »óÅ·Πº¹¿øÇÏ°í ¸ðµç µ¿Àû ÆäÀÌÁöµéÀ» SQL ÁÖÀÔ Ãë¾àÁ¡µé¿¡ ´ëÇØ °ËÁõÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2008-0098 (CVE) |
°ü·Ã URL |
27091 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|