| Ãë¾àÁ¡ID |
21024 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
CGI |
| »ó¼¼¼³¸í |
ÇØ´ç À¥¼¹ö¿¡ bnbform.cgi CGI ÇÁ·Î±×·¥ÀÌ ¼³Ä¡µÇ¾î ÀÖ´Ù. BNBFormÀº BigNoseBird¿¡ ÀÇÇØ ÇÁ·Î±×·¡¹ÖµÈ form processing scriptÀÌ´Ù. BNBFormÀº »ç¶÷µéÀÇ form Àü¼Û(submission)µé¿¡ ´ëÇØ ÀÚµ¿À¸·Î ÀÀ´ä ¸ÞÀÏÀ» º¸³»ÁÖ´Â ±â´ÉÀ» ÇÑ´Ù. ±×·¯³ª, ÀÌ CGI¸¦ ÀÌ¿ëÇÏ¸é ¿ÜºÎ¿¡¼ ¼¹ö³» ÆÄÀϽýºÅÛ¿¡ ÀÖ´Â ÀÓÀÇÀÇ ÆÄÀÏÀ» °¡Á®°¥ ¼ö ÀÖ´Ù. ÀÌ CGI¿¡¼ POST ¹æ½ÄÀÇ ¸Þ¼¼Áö Àü¼Û½Ã Hidden TypeÁß "automessage" À̸§¿¡ ´ëÇÑ Value·Î ¿øÇÏ´Â ÆÄÀϸíÀ» ÁÙ ¶§ °á°úÀûÀ¸·Î CGI´Â À¥¼¹öÀÇ UID ±ÇÇÑÀ¸·Î ¼¹ö¿¡ ÀÖ´Â ÇØ´ç ÆÄÀÏÀ» Àоî EmailÀ» ÅëÇØ ÆÄÀÏÀ» º¸³»ÁÖ°Ô µÈ´Ù.
¡Ø ÀÌ CGI¿¡ ´ëÇÑ ¿ø ¼Ò½ºÄÚµå´Âhttp://bignosebird.com/carchive/bnbform.shtml ¿¡¼ ¾òÀ» ¼ö ÀÖ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: bnbform.cgi CGI |
| ÇØ°áÃ¥ |
¼¹öÀÇ /cgi-bin µð·ºÅ丮·Î ºÎÅÍ »èÁ¦ÇØ¾ß ÇÑ´Ù. ÀÌ ½ºÅ©¸³Æ®°¡ ¹Ýµå½Ã ÇÊ¿äÇÏ´Ù¸é ¹®Á¦°¡ ¾ø´Â ÃֽйöÀüÀ» ±¸ÇÏ¿© ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù. |
| °ü·Ã URL |
CVE-1999-0937 (CVE) |
| °ü·Ã URL |
2147 (SecurityFocus) |
| °ü·Ã URL |
3093 (ISS) |
|