| Ãë¾àÁ¡ID |
21133 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
CGI |
| »ó¼¼¼³¸í |
ÀÌ "Netscape Web Publisher"°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù. Netscape Enterprise Server (3.51 and 3.6)¿¡ ÀÖ´Â Web Publishing ±â´ÉÀº ¿ø°ÝÁö¿¡¼ À¥¼¹ö·Î ÆÄÀÏÀ» Á¶ÀÛ(¿Ã¸®±â, ³»·Á¹Þ±â, º¯°æ)À» Áö¿øÇØ ÁÖ¸ç /publisher µð·ºÅ丮°¡ µðÆúÆ®·Î ¼³Ä¡µÇ¾î ÀÖ´Ù. Attacker´Â ¿ø°ÝÀ¸·Î À¥¼¹ö·Î ºÎÅÍ Web Publisher Java Applet ¼ÂÀ» ´Ù¿î·Îµå¹Þ±â À§ÇØ GET ¸í·ÉÀ» »ç¿ëÇÔÀ¸·Î½á ¼¹ö¿¡ ´ëÇÑ ºñÀΰ¡µÈ ¾×¼¼½º¸¦ ÇÒ ¼ö ÀÖ´Ù. ±×¸®°í³ª¼ Attacker´Â ¼¹ö³»ÀÇ ÀÓÀÇÀÇ ÆÄÀϵéÀ» ¸¶À½´ë·Î Á¶ÀÛ(upload, ³»·Á¹Þ±â, ¼öÁ¤)ÇÒ ¼ö ÀÖ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Netscape Web Publisher |
| ÇØ°áÃ¥ |
ÇÊ¿ä¾ø´Â ÆÐŰÁö¸é »èÁ¦ÇÏ¿©¾ß Çϸç, ¹Ýµå½Ã »ç¿ëÇÏ¿©¾ß ÇÏ´Â ÆÐŰÁö¶ó¸é ÃֽŠPatch¸¦ ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÑ´Ù. ¶ÇÇÑ Àΰ¡µÈ »ç¿ëÀÚ¸¸ÀÌ ¾×¼¼½ºÇÒ ¼ö ÀÖ°Ô Çϱâ À§Çؼ´Â WebPublisherÀÇ Access Control ModuleÀ» ¼³Á¤ÇÏ¿© »ç¿ëÇÏ¿©¾ß ÇÑ´Ù. |
| °ü·Ã URL |
CVE-2000-0237 (CVE) |
| °ü·Ã URL |
1075 (SecurityFocus) |
| °ü·Ã URL |
4202 (ISS) |
|