English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21216
À§Çèµµ 30
Æ÷Æ® 80, ¡¦
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç Allaire JRunÀº Ãë¾àÇÑ ¿¹Á¦ ÆÄÀϵéÀ» °¡Áö°í ÀÖ´Ù.
Allaire JRunÀº Java Servlet APIs¿Í Java Server Pages (JSP)¸¦ Áö¿øÇÏ´Â Java application ¼­¹öÀÌ´Ù. Allaire JRun 2.3.x¿¡ documentation, sample code, examples, ±×¸®°í applications, ȤÀº tutorials°¡ ¼­¹ö¿¡ ÀÖÀ» ¶§ »ó´ç¼öÀÇ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. À̵éÀº JRun°ú ÇÔ²² Ãâ½ÃµÇ¸ç Ãë¾àÁ¡µéÀ» ¾ø¾Ö±â À§Çؼ­´Â ¼öÀÛ¾÷À¸·Î Á¦°ÅÇØ¾ß ÇÑ´Ù.

¿ø°ÝÁöÀÇ »ç¿ëÀÚµéÀº ÀÌ ¿¹Á¦ ÆÄÀϵéÀ» ÀÌ¿ëÇÏ¿© ÆÄÀÏ ½Ã½ºÅÛ°ú ½Ã½ºÅÛ Configuation°ú °°Àº Áß¿äÇÑ Á¤º¸¸¦ º¸°Å³ª, ¼­¹ö»óÀÇ ´Ù¾çÇÑ ±â´ÉµéÀ» ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

¿¹¸¦µé¾î,
1. http://target/servlet/SessionServlet¸¦ ¾×¼¼½ºÇÏ¸é ¼­¹ö¿¡¼­ °ü¸®µÇ´Â ¸ðµç ÇöÀç HttpSession idµéÀÌ µð½ºÇ÷¹À̵ȴÙ.
2. viewsource.jsp (/jsp/jspsamp/jspexamples/viewsource.jsp) ÆÄÀÏÀº µðÆúÆ®·Î °æ·Î¸í üŷÀ» ÇÏÁö ¾Ê´Â´Ù. À̸¦ ÀÌ¿ëÇØ¼­ ¿ø°ÝÁö »ç¿ëÀÚµéÀº ¼­¹ö³»ÀÇ ÀÓÀÇÀÇ ÆÄÀϵéÀ» º¼ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/4774.php

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Web Server
ÇØ°áÃ¥ adobe À¥»çÀÌÆ® (http://www.adobe.com/support/jrun/updaters.html) ·ÎºÎÅÍ Jrun 2.3.3 ÀÌ»óÀÇ ÃֽйöÀü¸¦ ¹Þ¾Æ¼­ ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù. À¥¼­¹ö¿¡ ¼³Ä¡µÇ´Â ¿¹Á¦ ÆÄÀϵéÀº Á¦°ÅÇÏ´Â °ÍÀÌ ÁÁ´Ù.
°ü·Ã URL CVE-2000-0539,CVE-2000-0540 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)