English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21070
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í phf CGI´Â ±¸¹öÀüÀÇ NCSA³ª Apache ¼­¹ö¿¡ Æ÷ÇÔµÈ phone book »ùÇà ÇÁ·Î±×·¥À¸·Î ¿ÜºÎ¿¡¼­ ºê¶ó¿ìÀú¸¦ ÅëÇØ ½©ÀÌ ÀνÄÇÒ ¼ö ÀÖ´Â ÀÓÀÇÀÇ ¸í·ÉÀ» ½ÇÇàÇÒ ¼ö ÀÖ´Ù. escape_shell_cmd()Àº CGI ÇÁ·Î±×·¥¿¡ ÀÇÇØ ¹ß»ýµÈ ½©(shell)ÀÌ Ãß°¡ÀÇ ¸í·ÉÀ» °¡Áö°í ¸í·É¾î¸¦ ½ÇÇàÇÒ ¼ö ÀÖ°Ô ÇÏ´Â Á¦¾î ¹®ÀÚ(control characters)À» ÇÊÅ͸µÇÏ¿© shell-based ÇÔ¼ö(popen(), system())¸¦ È£ÃâÇÑ´Ù. ÀÌ ¶§ ¾î¶² ¹®ÀÚ´Â ÇÊÅ͸µ¿¡ ½ÇÆÐÇÏ¿© »ç¿ëÀÚ°¡ ÀÔ·ÂÇÑ ¸í·É¾î¸¦ root±ÇÇÑÀ¸·Î ½ÇÇà½ÃÄÑ ÁØ´Ù.

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Web Server
ÇØ°áÃ¥ Áï½Ã /cgi-bin µð·ºÅ丮³»¿¡ ÀÖ´Â phf ÆÄÀÏÀ» »èÁ¦ÇÑ´Ù.
°ü·Ã URL CVE-1999-0067 (CVE)
°ü·Ã URL 629 (SecurityFocus)
°ü·Ã URL 148 (ISS)