Ãë¾àÁ¡ID |
210153 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛÀÇ À¥ ¼¹ö´Â XPath ÀÎÁ§¼Ç¿¡ Ãë¾àÇÏ´Ù. XPath ÀÎÁ§¼ÇÀº Á¶ÀÛµÈ XPath(XML Path Language) Äõ¸®¸¦ º¸³¿À¸·Î½á ºñÁ¤»óÀûÀÎ µ¥ÀÌÅ͸¦ Äõ¸®ÇØ ¿Ã ¼ö ÀÖ´Â Ãë¾àÁ¡À¸·Î, XML ¹®¼¿¡ µ¥ÀÌÅ͸¦ ÀúÀåÇÏ´Â À¥»çÀÌÆ®´Â »ç¿ëÀÚ°¡ ÀÔ·ÂÇÑ ³»¿ëÀÇ µ¥ÀÌÅ͸¦ ã±â À§ÇØ XPath¸¦ »ç¿ëÇÏ°í, ÀÌ·± ÀÔ·ÂÀÌ ÇÊÅ͸µÀ̳ª º¸¾ÈÀ» °í·ÁÇÏÁö ¾ÊÀº ä XPath Äõ¸® ¾È¿¡ ÀԷµȴٸé À¥»çÀÌÆ®ÀÇ ·ÎÁ÷À» ¼Õ»ó½ÃÅ°°Å³ª ƯÁ¤ µ¥ÀÌÅ͸¦ ÃßÃâÇÒ ¼ö ÀÖ°Ô µÈ´Ù. ±×·¯¹Ç·Î XPath¸¦ »ç¿ë ½Ã »ç¿ëÀÚ ÀԷ°ª¿¡ ´ëÇÑ °ËÁõ ·ÎÁ÷À» Ãß°¡·Î ±¸ÇöÇØ¾ß ÇÑ´Ù.
* Âü°í »çÀÌÆ®: https://www.owasp.org/index.php/XPATH_Injection
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Any HTTP server Any version Any operating system Any version |
ÇØ°áÃ¥ |
´ÙÀ½°ú °°Àº Á¶Ä¡¸¦ ÃëÇØ¾ß ÇÑ´Ù. XPath Äõ¸®¿¡ ÀԷ°ªÀÌ ÀԷµǴ °æ¿ì, ÀԷ°ª °ËÁõÀ» ÅëÇØ ÇÊ¿ä ¹®ÀÚ¸¸À» ¹Þ¾ÆµéÀÌ°Ô ÇÑ´Ù. ¿¹¸¦ µé¾î, ( ) = ¡® [ ] : , * / µî XPath Äõ¸®¸¦ Æı«Çϴ Ư¼ö¹®ÀÚ´Â ÀÔ·ÂÇÏÁö ¸øÇÏ°Ô ÇÑ´Ù. |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|