| Ãë¾àÁ¡ID |
21208 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
CGI |
| »ó¼¼¼³¸í |
À¥¼¹ö¿¡ "dcforum.cgi" CGI°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù. DCScripts»ç¿¡ ÀÇÇØ °³¹ßµÈ DCForumÀº À¥±â¹ÝÀÇ ¸Þ¼¼Áö º¸µåµéÀ» ¸¸µé°í °ü¸®Çϴµ¥ »ç¿ëµÇ´Â CGI ½ºÅ©¸³Æ®ÀÌ´Ù. DCForum 6.0 ÀÌÇÏÀÇ ¹öÀüµé¿¡´Â ¼¹ö³»ÀÇ ÀÓÀÇÀÇ ÆÄÀÏÀ» Àо ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. »ç¿ëÀÚ ÀԷ¿¡ ´ëÇØ ÀûÀýÇÑ Ã¼Å©°úÁ¤À» °ÅÄ¡Áö ¾Ê±â ¶§¹®¿¡ Attacker´Â ¿ø°ÝÀ¸·Î ½Ã½ºÅÛ »óÀÇ ÀÓÀÇÀÇ ÆÄÀϵéÀ» http µ¥¸óÀÇ ±ÇÇÑ(root ȤÀº nobody)À¸·Î Àо ¼ö ÀÖ´Ù. ¸¸¾à Attacker°¡ dcforum.cgi ½ºÅ©¸³Æ®ÀÇ ¼Ò½º Äڵ带 º¸·Á°í ÇÑ´Ù¸é ±× ½ºÅ©¸³Æ® ÀÚü°¡ Áö¿öÁö¸é¼ ¼ºñ½º °ÅºÎ °ø°ÝÀÌ À¯¹ßµÈ´Ù.
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/static/5533.php http://www.net-security.org/vuln.php?id=443
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Web Server |
| ÇØ°áÃ¥ |
dcboard.cgi ¹× dcadmin.cgi ÆÄÀÏÀ» ¿¾î ´ÙÀ½°ú °°ÀÌ ¼öÁ¤ÇÑ´Ù. $r_in = \%in; ºÎºÐÀ» ´ÙÀ½°ú °°ÀÌ ¼öÁ¤ $r_in->{'forum'} =~ s/\W//g; |
| °ü·Ã URL |
CVE-2000-1132 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|