|  Ãë¾àÁ¡ID  | 
	             21298  | 
             
             
 	            |  À§Çèµµ  | 
	             30  |  
             
            
 	            |  Æ÷Æ®  | 
	             80, ...  | 
             		
            	
 	            |  ÇÁ·ÎÅäÄÝ  | 
	             TCP  | 
             	
            	
 	            |  ºÐ·ù  | 
	             CGI  | 
             			
            	
 	            |  »ó¼¼¼³¸í  | 
	             ÇØ´ç osCommerce´Â file_manager.php ½ºÅ©¸³Æ®¸¦ ÅëÇÑ µð·ºÅ丮 Ž»ö Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. osCommerce´Â °ø°³ ¼Ò½º ´Üü¿¡ ÀÇÇØ °³¹ßÀÌ ÁøÇàµÇ¾î ¿Â ¿Â¶óÀÎ ¼îÇÎÀ» À§ÇÑ e-commerce ¼Ö·ç¼ÇÀÌ´Ù. osCommerce 2.2ms1 ÀÌÇÏ ¹öÀüµéÀº »ç¿ëÀÚ°¡ °ø±ÞÇÑ ÀԷ°ªÀ» ÀûÀýÈ÷ ÇÊÅ͸µÇÏÁö ¸øÇÏ´Â °áÇÔÀ¸·Î ÀÎÇØ, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¿µÇâÀ» ¹Þ´Â À¥ ¼¹ö»óÀÇ ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐ¾î ³¾ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ´ÙÀ½°ú °°ÀÌ "dot dot(..)" ½ÃÄö½ºµéÀ» ÅëÇØ Ãë¾àÇÑ À¥ ¼¹ö»óÀÇ Àб⠰¡´ÉÇÑ ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐ¾î ³¾ ¼ö ÀÖ´Ù: http://[vulnerable.host]/oscommerce/admin/file_manager.php?action=download&filename=../../../../../../../../etc/passwd
  * Âü°í »çÀÌÆ®: http://www.securiteam.com/unixfocus/5GP0D2KCUQ.html http://archives.neohapsis.com/archives/bugtraq/2004-05/0162.html
  * ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: osCommerce Any version Microsoft Windows Any version Linux Any version Unix Any version  | 
             
            	
 	            |  ÇØ°áÃ¥  | 
	             osCommerce ´Ù¿î·Îµå À¥ »çÀÌÆ®ÀÎ http://www.oscommerce.com/solutions/downloads ¿¡¼ »õ·Î¿î ¼öÁ¤µÈ ¹öÀüÀÌ ´Ù¿î·Îµå °¡´ÉÇÒ ¶§ osCommerce °¡Àå ÃֽйöÀüÀ» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.  |   
             		
            	
 	            |  °ü·Ã URL  | 
	             CVE-2004-2021 (CVE) | 
             		
            	
 	            |   °ü·Ã URL  | 
	            10364 (SecurityFocus) |  
             
            
 	            |   °ü·Ã URL  | 
	            16174 (ISS) | 
             
    	
         
         |