| Ãë¾àÁ¡ID |
21048 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
CGI |
| »ó¼¼¼³¸í |
ÇØ´ç À¥¼¹ö¿¡ "guestbook.cgi" CGI°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù. ÀÌ CGI´Â ¿ÜºÎ¿¡¼ http µ¥¸óÀÇ ±ÇÇÑÀ¸·Î ¼¹ö»óÀÇ ÀÓÀÇÀÇ ¸í·ÉµéÀ» ¼öÇà½Ãų ¼ö ÀÖ°Ô ÇØÁÖ´Â Àß ¾Ë·ÁÁø º¸¾ÈÃë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. ÀÌ Ãë¾àÁ¡Àº Selena SolÀÇ guestbook¿¡ Á¸ÀçÇÑ´Ù.
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/static/321.php http://www.extropia.com/scripts/guestbook_security.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Web Server |
| ÇØ°áÃ¥ |
ÇÊ¿äÇÏÁö ¾Ê´Ù¸é À¥¼¹ö³»ÀÇ ±× CGI¸¦ Á¦°ÅÇÑ´Ù. ±×·¸Áö ¾ÊÀ¸¸é ´ÙÀ½°ú °°ÀÌ fixÇØ¼ »ç¿ëÇØ¾ß ÇÑ´Ù.
¹æ¹ý A: guestbook.setup ÆÄÀÏÀ» ¼öÁ¤ÇÏ¿© ÄÞ¸¶·Î ±¸ºÐµÈ @bad_words º¯¼ö¿¡ exec¸¦ µ¡ºÙ¿©¾ß ÇÑ´Ù.
¹æ¹ý B: guestbook.setup ÆÄÀÏÀ» ¼öÁ¤ÇÏ¿© @allow_html º¯¼ö¸¦ no·Î ¼ÂÇØ¾ß ÇÑ´Ù. |
| °ü·Ã URL |
CVE-1999-0237 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|