| Ãë¾àÁ¡ID |
21200 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
Servlet |
| »ó¼¼¼³¸í |
¿ÜºÎ¿¡¼ Oracle XSQL ÆäÀÌÁö¿¡ ´ëÇÑ Request¸¦ º¸³¾ ¶§ ¾ÇÀÇÀûÀÎ XSLT stylesheetÀÇ URLÀ» ÁÜÀ¸·Î½á, °ø°ÝÀÚ´Â Oracle XSQL ServletÀÌ ÀÓÀÇÀÇ Java Äڵ带 ¼öÇàÇϵµ·Ï ÇÒ ¼ö ÀÖ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Oracle XSQL Servlet |
| ÇØ°áÃ¥ |
OracleÀÌ Æ¯Á¤ XSQL servlet¿¡ ´ëÇØ Á¤ÇØÁ® ÀÖ´Â µ¿ÀÛ(default behaviour)ÀÌ Å¬¶óÀÌ¾ðÆ®°¡ Á¦°øÇÑ stylesheet·Î µ¿ÀÛÇÏÁö ¾Êµµ·Ï º¯°æÇÒ ¶§±îÁö, ÀÌ ¹®Á¦¸¦ ´ÙÀ½°ú °°ÀÌ Á¶Ä¡ÇØ¾ß ÇÑ´Ù.
ÇØ´ç À¥¼¹ö »óÀÇ ¸ðµç xsql ÆäÀÌÁöÀÇ document element¿¡ allow-client-style='no'¸¦ Ãß°¡ÇÑ´Ù. ÀÌ Á¡°ËÇ׸ñÀº airport.xsqlÀ̶ó´Â ¿¹Á¦ ÆäÀÌÁö¸¦ ÀÌ¿ëÇÏ¿© Ãë¾à¼º Å×½ºÆ®¸¦ ÇÏ¿´´Ù. ÀÌ ¿¹Á¦ ÆäÀÌÁö´Â Oracle XSQL ¼ºí¸´°ú ÇÔ²² Á¦°øµÈ´Ù. ¿¹Á¦ ÄÚµåµéÀº ´ë°³ ¸¹Àº ¹®Á¦¸¦ °¡Áö°í ÀÖÀ» ¼ö ÀÖÀ¸¹Ç·Î ¹Ýµå½Ã production ¼¹ö·Î ºÎÅÍ Á¦°ÅÇØ¾ß ÇÑ´Ù. |
| °ü·Ã URL |
CVE-2001-0126 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
5905 (ISS) |
|