English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21092
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥¼­¹ö¿¡ 'view_source' CGI°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù.
ÀÌ CGI ½ºÅ©¸³Æ®´Â ¸î¸î À¥¼­¹ö¿Í SCO Skunkware CD-ROMÀ» ÅëÇØ ¹èÆ÷µÇ¾ú´Ù. ºÒÇàÇϰԵµ 'view_source' cgi´Â Àμö¸¦ ÀûÀýÈ÷ üũÇÏÁö ¸øÇؼ­ ¿ÜºÎ¿¡¼­ À¥¼­¹ö³»ÀÇ ÀÓÀÇÀÇ ÆÄÀÏÀ» http µ¥¸óÀÇ ±ÇÇÑÀ¸·Î Àо ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
´ÙÀ½°ú °°Àº ¿äûÀ» º¸³¿À¸·Î½á ½Ã½ºÅÛ »óÀÇ ÀÓÀÇÀÇ ÆÄÀÏÀ» µð½ºÇ÷¹ÀÌÇØ º¼ ¼ö ÀÖ´Ù.

'http://www.target.com/cgi-bin/view_source?../../../../../../../etc/passwd'

* Âü°í »çÀÌÆ®:
http://www.netspace.org/cgi-bin/wa?A2=ind9702B&L=bugtraq&P=R64

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Web Server
ÇØ°áÃ¥ /cgi-bin µð·ºÅ丮·Î ºÎÅÍ ÇØ´ç CGI¸¦ »èÁ¦ÇÑ´Ù.
°ü·Ã URL CVE-1999-0174 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)