| Ãë¾àÁ¡ID |
21015 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
CGI |
| »ó¼¼¼³¸í |
ÇØ´ç À¥¼¹ö¿¡´Â "Expression Evaluator"¶ó ºÒ¸®´Â À¯Æ¿¸®Æ¼°¡ ¼³Ä¡µÈ Cold Fusion application ¼¹ö°¡ ÀÛµ¿ÁßÀÌ´Ù. Expression Evaluator´Â ColdFusionÀÇ 'expression evaluation feature'¿¡ °üÇÑ »ç¿ë¹æ¹ýÀ» »ç¿ëÀڵ鿡°Ô º¸¿©ÁÖ±â À§ÇÑ ¿¹Á¦ ½ºÅ©¸³Æ®ÀÌ´Ù. ±×·±µ¥, ÀÌ ½ºÅ©¸³Æ®µé Áß sendmail.cfm¿¡´Â ¿ÜºÎÀÇ Attacker°¡ ¼¹ö³»ÀÇ ÀÓÀÇÀÇ ÆÄÀÏÀ» °Ë»öÇØ º¼ ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Attacker°¡ Àμö¾øÀÌ sendmail.cfm¸¦ È£ÃâÇÏ¸é ½Ã½ºÅÛÀÇ date time stamp¸¦ Æ÷ÇÔÇÏ¿© µð·ºÅ丮 ±¸Á¶¸¦ º¸¿©ÁØ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Cold Fusion application ¼¹ö |
| ÇØ°áÃ¥ |
1. ´ÙÀ½ »çÀÌÆ®¿¡¼ Cold Fusion ÃֽйöÀü(4.0.1ÀÌ»ó)À¸·Î ¾÷µ¥ÀÌÆ®¸¦ ¼³Ä¡ÇÑ´Ù. http://www.adobe.com/support/coldfusion/downloads.html
2. ÇÊ¿äÇÏÁö ¾Ê´Ù¸é /CFDOCS/expeval¿¡ ÀÖ´Â ÇÁ·Î±×·¥µéÀ» ¸ðµÎ »èÁ¦ÇÑ´Ù. |
| °ü·Ã URL |
CVE-1999-0455,CVE-1999-0477 (CVE) |
| °ü·Ã URL |
115 (SecurityFocus) |
| °ü·Ã URL |
1740 (ISS) |
|