English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22003
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í IBM Net.Commerce¿¡ ÀÖ´Â MacroÀÎ orderdspc.d2w´Â SQL Injection °ø°Ý¿¡ Ãë¾àÇÏ´Ù.
IBM Net.Commerce´Â ÀüÀÚ»ó°Å·¡ À¥ »çÀÌÆ®¸¦ ±¸ÃàÇϰí È£½ºÆÃÇϱâ À§ÇÑ Çϵå¿þ¾î¿Í ¼ÒÇÁÆ®¿þ¾î¸¦ °âºñÇÑ Á¦Ç°ÀÌ´Ù. Ãë¾àÇÑ ½ºÅ©¸³Æ®¿¡ ´ëÇØ Àß Á¶ÀÛµÈ ¿äûÀ» º¸³»¸é ¼­¹ö´Â Net.Commerce µ¥ÀÌÅͺ£À̽º·ÎÀÇ ÀÓÀÇÀÇ ÁúÀÇÀÇ °á°úµéÀ» Æ÷ÇÔÇÑ °ü¸® ¸ñÀûÀÇ °èÁ¤µé°ú »ç¿ëÀÚ ÆÐ½º¿öµå ÆÄÀϵé°ú °°Àº Áß¿äÇÑ ½Ã½ºÅÛ Á¤º¸¸¦ ³ëÃâ½Ãų ¼ö ÀÖ´Ù. À̰ÍÀº °ø°ÝÀÚ°¡ DB2INST1 °èÁ¤ÀÇ ±ÇÇÑÀ» ȹµæÇÒ ¼ö ÀÖ°Ô Çϸç ÀáÀçÀûÀ¸·Î DB2INST1 »ç¿ëÀÚ·Î ÀÓÀÇÀÇ ½© ¸í·ÉµéÀ» ½ÇÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù.

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
IBM Net.Commerce 2.0 / 3.0
IBM Net.Commerce Hosting Server 3.1.1 / 3.1.2 / 3.2
IBM Net.Commerce Pro 3.1 / 3.1.1 / 3.1.2 / 3.2
IBM Net.Commerce Start 3.1 / 3.1.1 / 3.1.2 / 3.2
IBM WebSphere Commerce Suite MarketPlace 4.1
IBM WebSphere Commerce Suite Pro 4.1 / 4.1.1
IBM WebSphere Commerce Suite Service Provider 3.1.2 / 3.2
IBM WebSphere Commerce Suite Start 4.1 / 4.1.1

* Âü°í »çÀÌÆ®:
http://online.securityfocus.com/bid/2350
http://www.iss.net/security_center/static/6067.php
ÇØ°áÃ¥ Vender¿Í »óÀÇÇÏ¿© IBM Net.CommerceÀÇ °¡Àå ÃֽйöÀü(3.2 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

¿¹Á¦ MacroµéÀ» »èÁ¦Çϱâ À§Çؼ­´Â:

* °¢°¢ÀÇ Instance¿¡ ´ëÇØ HTML ¹®¼­ root¿¡ ÀÖ´Â db2www.ini¸¦ ã´Â´Ù.
* °¢°¢ÀÇ ini ÆÄÀÏÀÇ MACRO_PATH¸¦ »ìÆìºÁ¼­ ¸ðµç Macroµé¿¡ ´ëÇØ¼­ Á¦Ç°¿¡ ÇÊ¿äÇÑ °ÍÀÎÁö ±×¸®°í ¿¹Á¦µéÀÌ ¾Æ´ÑÁö¸¦ È®ÀÎÇÑ´Ù.
* Á¦Ç°¿¡ ÇÊ¿äÇÏÁö ¾ÊÀº µð·ºÅ丮µéÀ» »èÁ¦ÇÑ´Ù.
°ü·Ã URL CVE-2001-0319 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)