| Ãë¾àÁ¡ID |
21155 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
CGI |
| »ó¼¼¼³¸í |
À¥¼¹ö¿¡ "webdriver" CGI°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù. Informix Webdriver´Â Informix µ¥ÀÌÅͺ£À̽º¸¦ À§ÇÑ À¥±â¹ÝÀÇ ÀÎÅÍÆäÀ̽ºÀÌ´Ù. ¸¸¾à Attacker°¡ ¿ø°ÝÀ¸·Î URL(http://www.target.com/cgi-bin/webdriver)·Î ºÎÅÍ Á÷Á¢ Webdriver¸¦ ¾×¼¼½º ÇÒ ¼ö ÀÖ´Ù¸é À¥ ÆäÀÌÁö´Â Attacker¿¡°Ô µ¥ÀÌÅͺ£À̽º Á¤º¸¸¦ ¼öÁ¤Çϰųª »èÁ¦ÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù.
* À¯ÀÇ»çÇ× : secuiSCANÀº ´ÜÁö CGIÀÇ Á¸À縸À» Å×½ºÆ®Çϸç, ÀÌ CGI¿¡ ½ÇÁ¦ Ãë¾à¼ºÀÌ ÀÖ´ÂÁö´Â ÆÇ´ÜÇÏÁö ¾Ê´Â´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Web Server |
| ÇØ°áÃ¥ |
2014³â 6¿ù ÇöÀç ¹®Á¦¿¡ ´ëÇÑ ÇØ°á¹æ¹ýÀº ³ª¿ÍÀÖÁö ¾Ê´Ù. /cgi-bin µð·ºÅ丮·Î ºÎÅÍ ±× CGI¸¦ »èÁ¦ÇØ¾ß ÇÑ´Ù. |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
5833 (ISS) |
|