| Ãë¾àÁ¡ID |
22003 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
WWW |
| »ó¼¼¼³¸í |
IBM Net.Commerce¿¡ ÀÖ´Â MacroÀÎ orderdspc.d2w´Â SQL Injection °ø°Ý¿¡ Ãë¾àÇÏ´Ù. IBM Net.Commerce´Â ÀüÀÚ»ó°Å·¡ À¥ »çÀÌÆ®¸¦ ±¸ÃàÇϰí È£½ºÆÃÇϱâ À§ÇÑ Çϵå¿þ¾î¿Í ¼ÒÇÁÆ®¿þ¾î¸¦ °âºñÇÑ Á¦Ç°ÀÌ´Ù. Ãë¾àÇÑ ½ºÅ©¸³Æ®¿¡ ´ëÇØ Àß Á¶ÀÛµÈ ¿äûÀ» º¸³»¸é ¼¹ö´Â Net.Commerce µ¥ÀÌÅͺ£À̽º·ÎÀÇ ÀÓÀÇÀÇ ÁúÀÇÀÇ °á°úµéÀ» Æ÷ÇÔÇÑ °ü¸® ¸ñÀûÀÇ °èÁ¤µé°ú »ç¿ëÀÚ ÆÐ½º¿öµå ÆÄÀϵé°ú °°Àº Áß¿äÇÑ ½Ã½ºÅÛ Á¤º¸¸¦ ³ëÃâ½Ãų ¼ö ÀÖ´Ù. À̰ÍÀº °ø°ÝÀÚ°¡ DB2INST1 °èÁ¤ÀÇ ±ÇÇÑÀ» ȹµæÇÒ ¼ö ÀÖ°Ô Çϸç ÀáÀçÀûÀ¸·Î DB2INST1 »ç¿ëÀÚ·Î ÀÓÀÇÀÇ ½© ¸í·ÉµéÀ» ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: IBM Net.Commerce 2.0 / 3.0 IBM Net.Commerce Hosting Server 3.1.1 / 3.1.2 / 3.2 IBM Net.Commerce Pro 3.1 / 3.1.1 / 3.1.2 / 3.2 IBM Net.Commerce Start 3.1 / 3.1.1 / 3.1.2 / 3.2 IBM WebSphere Commerce Suite MarketPlace 4.1 IBM WebSphere Commerce Suite Pro 4.1 / 4.1.1 IBM WebSphere Commerce Suite Service Provider 3.1.2 / 3.2 IBM WebSphere Commerce Suite Start 4.1 / 4.1.1
* Âü°í »çÀÌÆ®: http://online.securityfocus.com/bid/2350 http://www.iss.net/security_center/static/6067.php |
| ÇØ°áÃ¥ |
Vender¿Í »óÀÇÇÏ¿© IBM Net.CommerceÀÇ °¡Àå ÃֽйöÀü(3.2 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
¿¹Á¦ MacroµéÀ» »èÁ¦Çϱâ À§Çؼ´Â:
* °¢°¢ÀÇ Instance¿¡ ´ëÇØ HTML ¹®¼ root¿¡ ÀÖ´Â db2www.ini¸¦ ã´Â´Ù. * °¢°¢ÀÇ ini ÆÄÀÏÀÇ MACRO_PATH¸¦ »ìÆìºÁ¼ ¸ðµç Macroµé¿¡ ´ëÇØ¼ Á¦Ç°¿¡ ÇÊ¿äÇÑ °ÍÀÎÁö ±×¸®°í ¿¹Á¦µéÀÌ ¾Æ´ÑÁö¸¦ È®ÀÎÇÑ´Ù. * Á¦Ç°¿¡ ÇÊ¿äÇÏÁö ¾ÊÀº µð·ºÅ丮µéÀ» »èÁ¦ÇÑ´Ù. |
| °ü·Ã URL |
CVE-2001-0319 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|