English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21012
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥¼­¹ö¿¡´Â "Expression Evaluator"¶ó ºÒ¸®´Â À¯Æ¿¸®Æ¼°¡ ¼³Ä¡µÈ Cold Fusion application ¼­¹ö°¡ ÀÛµ¿ÁßÀÌ´Ù. Expression Evaluator´Â ColdFusionÀÇ 'expression evaluation feature'¿¡ °üÇÑ »ç¿ë¹æ¹ýÀ» »ç¿ëÀڵ鿡°Ô º¸¿©ÁÖ±â À§ÇÑ ¿¹Á¦ ½ºÅ©¸³Æ®ÀÌ´Ù.
±×·±µ¥, ÀÌ ½ºÅ©¸³Æ®µé¿¡´Â ¿ÜºÎÀÇ Attacker°¡ ¼­¹ö³»ÀÇ ÀÓÀÇÀÇ ÆÄÀÏÀ» Àаųª »èÁ¦ÇÏ°Ô ÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Á¤»óÀûÀÎ °æ¿ì, ÀÌ ÇÁ·Î±×·¥Àº localhost(127.0.0.1)¿¡¼­¸¸ access°¡ °¡´ÉÇÏÁö¸¸ ÀÌ Ãë¾àÁ¡À¸·Î ÀÎÇØ ¾î¶² È£½ºÆ®·Î ºÎÅ͵µ Á÷ÀûÁ¢ÀÎ access°¡ °¡´ÉÇÏ´Ù. ¿©±â¿¡ ´õÇÏ¿© ÆÄÀϵéÀ» ¼­¹ö¿¡ ÆÄÀÏÀ» upload ÇÒ ¼ö ÀÖ¾î ½Ã½ºÅÛÀÇ shellÀ» µû³¾ ¼öµµ ÀÖ´Ù.

ÀÌ Ãë¾àÁ¡Àº ±âº»ÀûÀ¸·Î ´ÙÀ½ ¼¼°¡Áö ÆÄÀϵ鿡 ÀÖ´Ù.
- "/cfdocs/expeval/openfile.cfm"
- "/cfdocs/expeval/displayopenedfile.cfm"
- "/cfdocs/expeval/exprcalc.cfm".

ù¹øÂ° ÆÄÀÏÀº web formÀ» ÀÌ¿ëÇÏ¿© ÆÄÀÏÀ» uploadÇÒ ¼ö ÀÖÀ¸¸ç, µÎ¹øÂ° ÆÄÀÏÀº ¼­¹ö¿¡ ÆÄÀÏÀ» ÀúÀå °¡´ÉÀÖ´Ù. ¸¶Áö¸· ÆÄÀÏÀº uploadµÈ ÆÄÀÏÀÇ ³»¿ëÀ» Àо web form¿¡ ÆÄÀÏÀÇ ³»¿ëÀ» DisplayÇÏ°í ±×¸®°í uploadµÈ ÆÄÀÏÀ» »èÁ¦ÇÒ ¼ö ÀÖ´Ù.

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Cold Fusion application ¼­¹ö
ÇØ°áÃ¥ 1. ´ÙÀ½ »çÀÌÆ®¿¡¼­ Cold Fusion ÃֽйöÀü(4.0.1ÀÌ»ó)À¸·Î ¾÷µ¥ÀÌÆ®¸¦ ¼³Ä¡ÇÑ´Ù.
http://www.adobe.com/support/coldfusion/downloads.html

2. ÇÊ¿äÇÏÁö ¾Ê´Ù¸é /CFDOCS/expeval¿¡ ÀÖ´Â ÇÁ·Î±×·¥µéÀ» ¸ðµÎ »èÁ¦ÇÑ´Ù.
°ü·Ã URL CVE-1999-0455,CVE-1999-0477 (CVE)
°ü·Ã URL 115 (SecurityFocus)
°ü·Ã URL 1740 (ISS)