| Ãë¾àÁ¡ID |
21212 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
CGI |
| »ó¼¼¼³¸í |
À¥¼¹ö¿¡ "multihtml.pl" CGI°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù. MultiHTML´Â À¥ »çÀÌÆ®µéÀÌ SSI (Server Side Include) directive µéÀ» ÀÌ¿ëÇÏ¿© ´ÙÁßÀÇ À¥ ÆäÀÌÁö»ó¿¡ ÀÖ´Â °øÅë HTML ÄÄÆ÷³ÍÆ®µéÀ» µð½ºÇ÷¹ÀÌ Çϵµ·Ï ÇØ ÁÖ´Â CGI ½ºÅ©¸³Æ®ÀÌ´Ù. SSI directive¸¦ Æ÷ÇÔÇÑ À¥ ÆäÀÌÁö°¡ ¾×¼¼½ºµÉ ¶§ ±× ½ºÅ©¸³Æ®´Â À¥ ÆäÀÌÁö·Î ±âÁ¤ÀÇµÈ HTML ¼¼±×¸ÕÆ®¸¦ »ðÀÔÇÑ´Ù. Attacker´Â ±× CGIÀÇ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© ¾ÇÀÇÀûÀÎ ¸ñÀûÀ¸·Î '%00'ÀÌ Æ÷ÇÔµÈ URLÀ» ¸¸µé¾î º¸³¿À¸·Î½á ¿ø°ÝÀ¸·Î ½Ã½ºÅÛ »óÀÇ ÀÓÀÇÀÇ ÆÄÀÏÀ» º¼ ¼ö ÀÖ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Web Server |
| ÇØ°áÃ¥ |
2014³â 6¿ù ÇöÀç´Â ÇØ°áÃ¥ÀÌ ³ª¿ÍÀÖÁö ¾Ê´Ù. CGI-BIN µð·ºÅ丮·Î ºÎÅÍ "multihtml.pl" CGIÀ» »èÁ¦ÇØ¾ß ÇÑ´Ù. |
| °ü·Ã URL |
CVE-2000-0912 (CVE) |
| °ü·Ã URL |
6711 (SecurityFocus) |
| °ü·Ã URL |
5285 (ISS) |
|