English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21200
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Servlet
»ó¼¼¼³¸í ¿ÜºÎ¿¡¼­ Oracle XSQL ÆäÀÌÁö¿¡ ´ëÇÑ Request¸¦ º¸³¾ ¶§ ¾ÇÀÇÀûÀÎ XSLT stylesheetÀÇ URLÀ» ÁÜÀ¸·Î½á, °ø°ÝÀÚ´Â Oracle XSQL ServletÀÌ ÀÓÀÇÀÇ Java Äڵ带 ¼öÇàÇϵµ·Ï ÇÒ ¼ö ÀÖ´Ù.

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Oracle XSQL Servlet
ÇØ°áÃ¥ OracleÀÌ Æ¯Á¤ XSQL servlet¿¡ ´ëÇØ Á¤ÇØÁ® ÀÖ´Â µ¿ÀÛ(default behaviour)ÀÌ Å¬¶óÀÌ¾ðÆ®°¡ Á¦°øÇÑ stylesheet·Î µ¿ÀÛÇÏÁö ¾Êµµ·Ï º¯°æÇÒ ¶§±îÁö, ÀÌ ¹®Á¦¸¦ ´ÙÀ½°ú °°ÀÌ Á¶Ä¡ÇØ¾ß ÇÑ´Ù.

ÇØ´ç À¥¼­¹ö »óÀÇ ¸ðµç xsql ÆäÀÌÁöÀÇ document element¿¡ allow-client-style='no'¸¦ Ãß°¡ÇÑ´Ù.
ÀÌ Á¡°ËÇ׸ñÀº airport.xsqlÀ̶ó´Â ¿¹Á¦ ÆäÀÌÁö¸¦ ÀÌ¿ëÇÏ¿© Ãë¾à¼º Å×½ºÆ®¸¦ ÇÏ¿´´Ù. ÀÌ ¿¹Á¦ ÆäÀÌÁö´Â Oracle XSQL ¼­ºí¸´°ú ÇÔ²² Á¦°øµÈ´Ù. ¿¹Á¦ ÄÚµåµéÀº ´ë°³ ¸¹Àº ¹®Á¦¸¦ °¡Áö°í ÀÖÀ» ¼ö ÀÖÀ¸¹Ç·Î ¹Ýµå½Ã production ¼­¹ö·Î ºÎÅÍ Á¦°ÅÇØ¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2001-0126 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL 5905 (ISS)