English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21666
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç Jaws ¼ÒÇÁÆ®¿þ¾î´Â ´ÙÁßÀÇ ÀÔ·Â °ËÁõ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. Jaws´Â PHP·Î Á¦ÀÛµÈ µ¿Àû À¥ »çÀÌÆ®µéÀ» ±¸ÃàÇϱâ À§ÇÑ ÇÁ·¹ÀÓ¿öÅ© ¹× ÄÜÅÙÆ® °ü¸® ½Ã½ºÅÛÀÌ´Ù. Jaws ¹öÀü 0.3 BETA¿Í ±× ÀÌÀü ¹öÀüµéÀº ´ÙÁßÀÇ ÀÔ·Â °ËÁõ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ´ÙÀ½°ú °°Àº Ãë¾àÁ¡µéÀ» ÀÌ¿ëÇÏ´Â ´Ù¾çÇÑ °ø°ÝµéÀ» ¼öÇàÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù:

1) Cross-Site Scripting Ãë¾àÁ¡
2) µð·ºÅ丮 Ž»ö Ãë¾àÁ¡ (index.php ½ºÅ©¸³Æ®ÀÇ gadget Àμö¸¦ ÅëÇØ)
3) ÀÎÁõ ¿ìȸ Ãë¾àÁ¡

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0226.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Jaws ¹öÀü 0.3 BETA¿Í ±× ÀÌÀü ¹öÀüµé
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ Jaws À¥ »çÀÌÆ®ÀÎ http://www.jaws.com ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â JawsÀÇ °¡Àå ÃֽŠ¹öÀü(0.5 ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2004-2443,CVE-2004-2444,CVE-2004-2445 (CVE)
°ü·Ã URL 10670 (SecurityFocus)
°ü·Ã URL 16614,16617,16619,16620,16621,16622 (ISS)