English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 210152
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛÀÇ À¥ ¼­¹ö´Â SSI(Server-Side Includes) ÀÎÁ§¼Ç °ø°Ý¿¡ Ãë¾àÇÏ´Ù.
SSI(Server-Side Includes) ÀÎÁ§¼ÇÀº HTML ¹®¼­ ³» ÀԷ¹ÞÀº º¯¼ö°ªÀ» ¼­¹ö Ãø¿¡¼­ ó¸®ÇÒ ¶§ ºÎÀûÀýÇÑ ¸í·É¹®ÀÌ Æ÷ÇÔ ¹× ½ÇÇàµÇ¾î ¼­¹öÀÇ µ¥ÀÌÅÍ°¡ À¯ÃâµÇ´Â Ãë¾àÁ¡ÀÌ´Ù.
SSI´Â CGI ÇÁ·Î±×·¥À» ÀÛ¼ºÇϰųª ȤÀº ¼­¹ö»çÀÌµå ½ºÅ©¸³Æ®¸¦ »ç¿ëÇÏ´Â ¾ð¾î·Î, À¥ ¼­¹ö°¡ »ç¿ëÀÚ¿¡°Ô ÆäÀÌÁö¸¦ Á¦°øÇϱâ Àü¿¡ ±¸¹®À» Çؼ®Çϵµ·Ï Áö½ÃÇÏ´Â ¿ªÇÒÀ» ÇÑ´Ù. SSI ±¸ÇöÀº ¿ÜºÎÀÇ CGI ½ºÅ©¸³Æ®³ª ½Ã½ºÅÛ ¸í·É¾îµéÀ» ½ÇÇàÇÒ ¼ö ÀÖÀ¸¹Ç·Î »ç¿ëÀÚ ÀԷ°ª¿¡ ´ëÇÑ °ËÁõ ·ÎÁ÷À» Ãß°¡·Î ±¸ÇöÇØ¾ß ÇÑ´Ù.

* Âü°í »çÀÌÆ®:
https://www.owasp.org/index.php/Server-Side_Includes_(SSI)_Injection

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Any HTTP server Any version
Any operating system Any version
ÇØ°áÃ¥ ´ÙÀ½°ú °°Àº Á¶Ä¡¸¦ ÃëÇØ¾ß ÇÑ´Ù.
1. »ç¿ëÀÚ ÀÔ·ÂÀ¸·Î »ç¿ë °¡´ÉÇÑ ¹®ÀÚµéÀ» Á¤ÇØ¾ß ÇÑ´Ù.
2. Á¤ÇØÁø ¹®ÀÚµéÀ» Á¦¿ÜÇÑ ³ª¸ÓÁö ¸ðµç ¹®ÀÚµéÀ» ÇÊÅ͸µ ÇØ¾ß ÇÑ´Ù.
¿¹¸¦ µé¾î Ư¼ö ¹®ÀÚÀÇ °æ¿ì ´ÙÀ½°ú °°ÀÌ º¯°æÇØ¾ß ÇÑ´Ù.
< -> %lt;
> -> >
" -> "
( -> (
) -> )
# -> #
& -> &
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)