Ãë¾àÁ¡ID |
210152 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛÀÇ À¥ ¼¹ö´Â SSI(Server-Side Includes) ÀÎÁ§¼Ç °ø°Ý¿¡ Ãë¾àÇÏ´Ù. SSI(Server-Side Includes) ÀÎÁ§¼ÇÀº HTML ¹®¼ ³» ÀԷ¹ÞÀº º¯¼ö°ªÀ» ¼¹ö Ãø¿¡¼ ó¸®ÇÒ ¶§ ºÎÀûÀýÇÑ ¸í·É¹®ÀÌ Æ÷ÇÔ ¹× ½ÇÇàµÇ¾î ¼¹öÀÇ µ¥ÀÌÅÍ°¡ À¯ÃâµÇ´Â Ãë¾àÁ¡ÀÌ´Ù. SSI´Â CGI ÇÁ·Î±×·¥À» ÀÛ¼ºÇϰųª ȤÀº ¼¹ö»çÀÌµå ½ºÅ©¸³Æ®¸¦ »ç¿ëÇÏ´Â ¾ð¾î·Î, À¥ ¼¹ö°¡ »ç¿ëÀÚ¿¡°Ô ÆäÀÌÁö¸¦ Á¦°øÇϱâ Àü¿¡ ±¸¹®À» Çؼ®Çϵµ·Ï Áö½ÃÇÏ´Â ¿ªÇÒÀ» ÇÑ´Ù. SSI ±¸ÇöÀº ¿ÜºÎÀÇ CGI ½ºÅ©¸³Æ®³ª ½Ã½ºÅÛ ¸í·É¾îµéÀ» ½ÇÇàÇÒ ¼ö ÀÖÀ¸¹Ç·Î »ç¿ëÀÚ ÀԷ°ª¿¡ ´ëÇÑ °ËÁõ ·ÎÁ÷À» Ãß°¡·Î ±¸ÇöÇØ¾ß ÇÑ´Ù.
* Âü°í »çÀÌÆ®: https://www.owasp.org/index.php/Server-Side_Includes_(SSI)_Injection
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Any HTTP server Any version Any operating system Any version |
ÇØ°áÃ¥ |
´ÙÀ½°ú °°Àº Á¶Ä¡¸¦ ÃëÇØ¾ß ÇÑ´Ù. 1. »ç¿ëÀÚ ÀÔ·ÂÀ¸·Î »ç¿ë °¡´ÉÇÑ ¹®ÀÚµéÀ» Á¤ÇØ¾ß ÇÑ´Ù. 2. Á¤ÇØÁø ¹®ÀÚµéÀ» Á¦¿ÜÇÑ ³ª¸ÓÁö ¸ðµç ¹®ÀÚµéÀ» ÇÊÅ͸µ ÇØ¾ß ÇÑ´Ù. ¿¹¸¦ µé¾î Ư¼ö ¹®ÀÚÀÇ °æ¿ì ´ÙÀ½°ú °°ÀÌ º¯°æÇØ¾ß ÇÑ´Ù. < -> %lt; > -> > " -> " ( -> ( ) -> ) # -> # & -> & |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|