| Ãë¾àÁ¡ID |
21187 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
CGI |
| »ó¼¼¼³¸í |
IIS¼¹ö¿¡ µðÆúÆ®·Î ¼³Ä¡µÇ´Â ¸¹Àº ÆÄÀϵéÀÌ ¾ÇÀÇÀûÀÎ »ç¿ëÀÚ¿¡°Ô ¼¹ö³» ÆÄÀϽýºÅÛÀ̳ª ¼Ò½ºÆÄÀϵ鿡 ´ëÇÑ ºÒÇÊ¿äÇÑ ¸¹Àº Á¤º¸¸¦ Á¦°øÇÑ´Ù. ƯÈ÷ viewcode.asp´Â ¿ÜºÎ »ç¿ëÀÚ¿¡°Ô À¥¼¹öÀÇ Çϵåµð½ºÅ©»ó¿¡ ÀÖ´Â ¾î¶² ÆÄÀÏÀ» Àо ¼ö ÀÖ´Â Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. ¿¹¸¦µé¾î ´ÙÀ½°ú °°Àº URLÀ» ÁÖ¸é autoexec.batÆÄÀÏÀ» Àо ¼ö ÀÖ´Ù. http://target.com/pathto/viewcode.asp?source=../../../../autoexec.bat
* Âü°í »çÀÌÆ®: http://www.microsoft.com/technet/security/bulletin/ms99-013.asp
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Microsoft IIS Server |
| ÇØ°áÃ¥ |
ÇÊ¿äÇÏÁö ¾Ê´Ù¸é ÀÌ ÆÄÀϵéÀ» »èÁ¦ÇØ¾ß ÇÑ´Ù. ±×·¸Áö ¾ÊÀ¸¸é ±× ÆÄÀϵéÀÌ ÀÐÇôÁöÁö ¾Êµµ·Ï Àû´çÇÑ Á¢±Ù ±ÇÇÑÀ» ¼³Á¤ÇØ ³ö¾ß ÇÑ´Ù. |
| °ü·Ã URL |
CVE-1999-0737 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
2382 (ISS) |
|