English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21040
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥¼­¹ö¿¡ '/cgi-bin/ews/ews/architext_query.pl' CGI°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù.
Excite for Web Servers (EWS) 1.1 ÀÌÇÏÀÇ ¹öÀü¿¡ ¼³Ä¡µÈ CGI´Â shell·Î °Ç³×´Â meta ¹®ÀÚµéÀ» ÇØ¼®(parse)ÇÏ´Â °úÁ¤¿¡¼­ ¿ÜºÎ »ç¿ëÀÚ°¡ http µ¥¸óÀÇ ±ÇÇÑÀ¸·Î ¼­¹ö³»ÀÇ ÀÓÀÇÀÇ ¸í·ÉµéÀ» ½ÇÇà½Ãų ¼ö ÀÖ´Â Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. ÀÌ Ãë¾àÁ¡Àº EWS°¡ µ¿ÀÛÇÏ´Â Windows NT¿Í UNIX ½Ã½ºÅÛ ¸ðµÎ¿¡¼­ ¿µÇâÀ» ¹ÌÄ£´Ù.
¡Ø CERT:VB-98.01.excite

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/1418.php
http://www.cert.org/advisories/CA-1998-01.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Web Server
ÇØ°áÃ¥ ¹öÀü 1.1¿¡¼­´Â ÀÌ Ãë¾àÁ¡ÀÌ ÇØ°áµÇ¾ú´Ù. ÇÏÁö¸¸ ¹öÀü 1.1 ÆÇÀ¸·Î ´Ù¼ö°³ÀÇ EWS°¡ Ãâ½ÃµÇ¾î ¹öÀü number ÀÚü·Î´Â Ãë¾àÁ¡ÀÇ À¯¹«¸¦ ÆÇº°ÇÏ±â ¾î·Æ´Ù. °¡´ÉÇÑÇÑ Excite¿¡ ÀÇÇØ ¹èÆ÷µÇ´Â EWS 1.1 º¸´Ù »óÀ§ÀÇ ¹öÀüÀ¸·Î ¾÷±×·¹À̵åÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-1999-0279 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)