English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 210153
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛÀÇ À¥ ¼­¹ö´Â XPath ÀÎÁ§¼Ç¿¡ Ãë¾àÇÏ´Ù.
XPath ÀÎÁ§¼ÇÀº Á¶ÀÛµÈ XPath(XML Path Language) Äõ¸®¸¦ º¸³¿À¸·Î½á ºñÁ¤»óÀûÀÎ µ¥ÀÌÅ͸¦ Äõ¸®ÇØ ¿Ã ¼ö ÀÖ´Â Ãë¾àÁ¡À¸·Î, XML ¹®¼­¿¡ µ¥ÀÌÅ͸¦ ÀúÀåÇÏ´Â À¥»çÀÌÆ®´Â »ç¿ëÀÚ°¡ ÀÔ·ÂÇÑ ³»¿ëÀÇ µ¥ÀÌÅ͸¦ ã±â À§ÇØ XPath¸¦ »ç¿ëÇÏ°í, ÀÌ·± ÀÔ·ÂÀÌ ÇÊÅ͸µÀ̳ª º¸¾ÈÀ» °í·ÁÇÏÁö ¾ÊÀº ä XPath Äõ¸® ¾È¿¡ ÀԷµȴٸé À¥»çÀÌÆ®ÀÇ ·ÎÁ÷À» ¼Õ»ó½ÃÅ°°Å³ª ƯÁ¤ µ¥ÀÌÅ͸¦ ÃßÃâÇÒ ¼ö ÀÖ°Ô µÈ´Ù. ±×·¯¹Ç·Î XPath¸¦ »ç¿ë ½Ã »ç¿ëÀÚ ÀԷ°ª¿¡ ´ëÇÑ °ËÁõ ·ÎÁ÷À» Ãß°¡·Î ±¸ÇöÇØ¾ß ÇÑ´Ù.

* Âü°í »çÀÌÆ®:
https://www.owasp.org/index.php/XPATH_Injection

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Any HTTP server Any version
Any operating system Any version
ÇØ°áÃ¥ ´ÙÀ½°ú °°Àº Á¶Ä¡¸¦ ÃëÇØ¾ß ÇÑ´Ù.
XPath Äõ¸®¿¡ ÀԷ°ªÀÌ ÀԷµǴ °æ¿ì, ÀԷ°ª °ËÁõÀ» ÅëÇØ ÇÊ¿ä ¹®ÀÚ¸¸À» ¹Þ¾ÆµéÀÌ°Ô ÇÑ´Ù.
¿¹¸¦ µé¾î, ( ) = ¡® [ ] : , * / µî XPath Äõ¸®¸¦ Æı«Çϴ Ư¼ö¹®ÀÚ´Â ÀÔ·ÂÇÏÁö ¸øÇÏ°Ô ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)