English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21201
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Servlet
»ó¼¼¼³¸í UnifyÀÇ eWave ServletExecÀº Apache, IIS, Netscape µî°ú °°Àº ¸¹ÀÌ ¾²ÀÌ´Â À¥¼­¹öµé¿¡ plug-inÀ¸·Î½á »ç¿ëµÇ´Â JSP (Java Server Pages)¿Í Java Servlet ¿£ÁøÀÌ´Ù.

eWave ServletExec 3.0C ÀÌÇÏÀÇ ¹öÀüµéÀº "UploadServlet" servletÀ» Æ÷ÇÔÇϰí Àִµ¥ ÀÌ servletÀº Attacker°¡ ¿ø°ÝÀ¸·Î ÀÓÀÇÀÇ ÆÄÀϵéÀ» ¼­¹ö»ó¿¡ upload ÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù. Attacker´Â "UploadServlet" servletÀ» È£ÃâÇϱâ À§ÇØ path¿¡ "/servlet/com.unify.ewave.servletexec.UploadServlet"À» Æ÷ÇÔÇÏ´Â URLÀ» À¥¼­¹ö¿¡ ¿äû(Request)ÇÑ´Ù. Attacker´Â ÀÌ ¹æ¹ýÀ¸·Î ÀÓÀÇÀÇ ÆÄÀϵéÀ» upload ÇÒ ¼ö ÀÖÀ¸¸ç ¼­¹ö»ó¿¡ ±× ÆÄÀϵéÀ» ½ÇÇà½Ãų ¼öµµ ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/5450.php
http://www.servletexec.com/downloads/
ÇØ°áÃ¥ eWave ServletExecÀÇ ÃֽйöÀü (3.0E ÀÌÈÄ ¹öÀü)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. ¾÷±×·¹À̵å´Â Unify eWave ServletExec À¥ »çÀÌÆ®(ÂüÁ¶ »çÀÌÆ®)¿¡¼­ ´Ù¿î·Îµå ¹ÞÀ» ¼ö ÀÖ´Ù.
°ü·Ã URL CVE-2000-1024 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)