| Ãë¾àÁ¡ID |
22091 |
| À§Çèµµ |
20 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
Servlet |
| »ó¼¼¼³¸í |
ÇØ´ç Tomcat ¼ºí¸´ ¼¹ö´Â Á¶ÀÛµÈ ¿äûÀ» ÀÌ¿ëÇÑ .jsp ÆÄÀÏÀ» ¿äûÇÒ °æ¿ì À¥ rootÀÇ ¹°¸®Àû °æ·Î¸íÀ» ³ëÃâ½ÃŲ´Ù. °ø°ÝÀÚ°¡ ÀÌ °áÇÔÀ» ÀÌ¿ëÇÏ¸é ´ë»ó È£½ºÆ®ÀÇ ÆÄÀϽýºÅÛ ·¹À̾ƿô¿¡ ´ëÇÑ ´õ ¸¹Àº Áö½ÄÀ» ¾ò¾î°¥ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ´ÙÀ½°ú °°Àº ¹æ¹ý°ú °°ÀÌ, 222±ä ¹ÙÀÌÆ® ÀÌ»óÀÇ ºñÁ¤»óÀûÀÎ ±ä ¿äûÀ̳ª Á¶ÀÛµÈ ¿äûÀ» º¸³¾ °æ¿ì À¥¼¹öÀÇ ¼³Ä¡°æ·Î¸¦ ¾òÀ» ¼ö ÀÖ´Ù.
$ lynx http://localhost:8080/`perl -e 'print "A" x 223'`.jsp $ lynx http://localhost:8080/:/x.jsp $ lynx http://localhost:8080/~../x.jsp
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/bid/3199 http://www.iss.net/security_center/static/6997.php |
| ÇØ°áÃ¥ |
HP-UX 11 »ç¿ëÀÚ´Â ´ÙÀ½ ¸µÅ©¸¦ ÂüÁ¶ÇÏ¿© ÀûÀýÇÑ ÆÐÄ¡¸¦ ¼³Ä¡ÇØ¾ß ÇÑ´Ù. http://www.securityfocus.com/advisories/3613
±× ¿ÜÀÇ ½Ã½ºÅÛÀº Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î½á »ç¿ëÀÚµéÀÌ web.xml¿¡ ÀÖ´Â <error-page> Áö½ÃÀÚ¸¦ ÀÌ¿ëÇÑ ¿¡·¯ ÆäÀÌÁöµéÀ» Á÷Á¢ ¼öÁ¤ÇÏ¿©¾ß ÇÑ´Ù. |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|