Ãë¾àÁ¡ID |
21600 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç WebAPP ¼ÒÇÁÆ®¿þ¾î´Â index.cgi ½ºÅ©¸³Æ®¿¡ ÀÖ´Â µð·ºÅ丮 Ž»ö Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. WebAPP´Â Unix ¿î¿µÃ¼Á¦¸¦ À§ÇØ Perl·Î Á¦ÀÛµÈ ¹«·á·Î »ç¿ë °¡´ÉÇÑ ¿ÀÇ ¼Ò½º À¥ Æ÷ÅÐ ½Ã½ºÅÛÀÌ´Ù. WebAPP ¹öÀü 0.9.9.1 ÀÌÇÏÀÇ ¹öÀüµéÀº 'index.cgi' ½ºÅ©¸³Æ®ÀÇ 'viewcat' Àμö·Î °Ç³×Áø »ç¿ëÀÚ°¡ Á¦°øÇÑ ÀԷ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ ÇÊÅ͸µÀ¸·Î ÀÎÇÏ¿© ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ À¥ rootÀÇ ¿ÜºÎ¿¡ ÀÖ´Â ÆÄÀÏÀ» º¼ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. "dot dot" ½ÃÄö½º(/../)µéÀ» Æ÷ÇÔÇÏ´Â Àß Á¶ÀÛµÈ URLÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â µð·ºÅ丮µéÀ» Ž»öÇÏ°í À¥ ¼¹ö¿¡ ÀÖ´Â ÀÓÀÇÀÇ ÆÄÀÏÀ» º¼ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://marc.theaimsgroup.com/?l=bugtraq&m=109336268002879&w=2 http://secunia.com/advisories/12373
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: WebAPP ¹öÀü 0.9.9.1 ÀÌÇÏÀÇ ¹öÀüµé Unix Any version |
ÇØ°áÃ¥ |
´ÙÀ½ »çÀÌÆ®¸¦ Âü°íÇÏ¿© WebAPPÀÇ °¡Àå ÃֽŠ¹öÀü(0.9.9.2 ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å Çϰųª ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù. http://www.bestfreewaredownload.com/freeware/t-free-webapp-freeware-mpdhhrpn.html |
°ü·Ã URL |
CVE-2004-1742 (CVE) |
°ü·Ã URL |
11028 (SecurityFocus) |
°ü·Ã URL |
17100 (ISS) |
|