Ãë¾àÁ¡ID |
210158 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛÀÇ À¥ ¼¹ö´Â RFI(Remote File Inclusion) °ø°Ý¿¡ Ãë¾àÇÏ´Ù. RFI(Remote File Inclusion) Ãë¾àÁ¡À» ÀÌ¿ëÇÑ °ø°ÝÀº °ø°ÝÀÚ°¡ ¾Ç¼º ½ºÅ©¸³Æ®¸¦ ¼¹ö½º ¼¹ö¿¡ Àü´ÞÇÏ¿© ÇØ´ç ÆäÀÌÁö¸¦ ÅëÇÏ¿© Àü´ÞÇÑ ¾Ç¼º Äڵ尡 ½ÇÇàµÇµµ·Ï ÇÏ´Â °ÍÀÌ´Ù. ÇѸ¶µð·Î Ç¥ÇöÇϸé À¥ ¾îÇø®ÄÉÀ̼ǿ¡ °ø°ÝÀÚ ÀÚ½ÅÀÇ Äڵ带 ¿ø°ÝÀ¸·Î »ðÀÔ °¡´ÉÇÏ´Ù´Â ¶æÀÌ´Ù. PHPÀÇ °æ¿ì $_GET, $_POST µîÀ¸·Î °ªÀ» Àü´Þ ¹Þ´Â °úÁ¤¿¡¼ ÇØ´ç °ªÀ» ¿Ã¹Ù¸£°Ô °Ë»çÇÏÁö ¸øÇÏ¿© ¹ß»ýÇÑ´Ù. ´ÙÀ½ ¿¹Á¦¿¡¼´Â 'COLOR' °ª¿¡ ¿ÜºÎ ÆÄÀÏÀÇ °æ·Î¸¦ Á÷Á¢ ÀÔ·ÂÇÒ °æ¿ì °ø°ÝÀÚ°¡ ÀǵµÇÏ´Â ÆÄÀÏÀÌ ½ÇÇàµÉ ¼ö ÀÖ´Ù. <?php if ( isset( $_GET['COLOR'] ) ) { include( $_GET['COLOR'] . '.php' ); } ?>
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Any HTTP server Any version Any operating system Any version |
ÇØ°áÃ¥ |
´ÙÀ½°ú °°Àº Á¶Ä¡¸¦ ÃëÇØ¾ß ÇÑ´Ù. ¿ÜºÎÀÇ ÆÄÀÏÀÌ ÀԷµǴ °æ¿ì, ÀԷ°ª °ËÁõÀ» ÅëÇØ ÇÊ¿ä ¹®ÀÚ¸¸À» ¹Þ¾ÆµéÀÌ°Ô ÇÑ´Ù. ¿¹¸¦ µé¾î http:// °ªÀº ÇÊÅ͸µ µÇ¾î¾ß ÇÑ´Ù. |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|