English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22053
À§Çèµµ 20
Æ÷Æ® 80, ¡¦
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Servlet
»ó¼¼¼³¸í À¥¼­¹ö¿¡ Snoop tomcatÀÇ servletÀÌ ¼³Ä¡µÇ¾î ÀÖ´Ù (/examples/jsp/snp/anything.snp). Jakarta TomcatÀº Java Servlet Pages (JSP)¿Í Java servlets¸¦ Áö¿øÇϱâ À§ÇØ Apache À¥¼­¹ö¿¡ »ç¿ëµÇ´Â Java application ¼­¹öÀÌ´Ù.
Apache ¼­¹ö¿¡ ¼³Ä¡µÇ´Â Jakarta Tomcat 3.1¿Í 3.0¿¡ ÀÖ´Â Snoop servletÀº .snp È®ÀåÀÚ·Î µÈ Á¸ÀçÇÏÁö ¾Ê´Â URLÀ» ¿äûÇÒ ¶§ À¥¼­¹ö¿¡ °üÇÑ Áß¿äÇÑ Á¤º¸¸¦ ´©Ãâ½Ãų ¼ö ÀÖ´Ù. ±× Á¤º¸¿¡´Â »ç¿ëÁßÀÎ PATH³ª È£½ºÆ®ÀÇ Ä¿³Î ¹öÀü µî°ú °°Àº °ÍµéÀÌ Æ÷ÇԵȴÙ. À̰ÍÀº Attacker¿¡°Ô ÇØ´ç ¼­¹ö¿¡ ´ëÇÑ º¸´Ù ´õ Á¤È®ÇÑ Á¤º¸¸¦ ÁÖ¾î Á» ´õ Á¤¹ÐÇÑ AttackÀ» ÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù.
ÇØ°áÃ¥ ÇØ´ç servlet (/examples/jsp/snp/anything.snp)À» »èÁ¦ÇÑ´Ù.
°ü·Ã URL CVE-2000-0760 (CVE)
°ü·Ã URL 1532 (SecurityFocus)
°ü·Ã URL 4968 (ISS)