| Ãë¾àÁ¡ID |
22092 |
| À§Çèµµ |
20 |
| Æ÷Æ® |
8080 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
Servlet |
| »ó¼¼¼³¸í |
ÇØ´ç Jakarta Tomcat ¼¹ö´Â º¸¾È»ó Áß¿äÇÑ °æ·Î¸í Á¤º¸¸¦ ³ëÃâ½ÃŲ´Ù. Jakarta TomcatÀº Java Servlet Pages (JSP)¿Í Java servlet µéÀ» Áö¿øÇÒ ¼ö ÀÖµµ·Ï Apache À¥ ¼¹öµé°ú ÇÔ²² ¾²ÀÌ´Â Java ¾ÖÇø®ÄÉÀÌ¼Ç ¼¹öÀÌ´Ù. »ç¿ëÀÚ°¡ Á¸ÀçÇÏÁö ¾Ê´Â JSP ÆÄÀÏÀÇ URLÀ» ¿äûÇÒ ¶§, À¥ µð·ºÅ丮·ÎÀÇ ¹°¸®Àû °æ·Î¸íÀÌ ¿¡·¯ ¸Þ½ÃÁöÀÇ ÇÑ ºÎºÐÀ¸·Î½á ¼¹ö¿¡ ÀÇÇØ Á¦°øµÈ´Ù. ÀÌ ¹æ¹ýÀÌ Attacker¿¡°Ô´Â °ø°Ý¿¡ µµ¿òÀÌ µÇ´Â À¥¼¹öÀÇ ÆÄÀÏ ±¸Á¶¿¡ ´ëÇÑ Á¤º¸¸¦ ¾ò´Âµ¥ »ç¿ëµÉ ¼ö ÀÖ´Ù. ´ÙÀ½°ú °°Àº ¿äû¿¡ ÀÇÇØ À¥ µð·ºÅ丮·ÎÀÇ °æ·Î¸íÀ» º¼ ¼ö ÀÖ´Ù: http://www.example.com/anything.jsp
Error: 404 Location: /anything.jsp
JSP file "/appsrv2/jakarta-tomcat/webapps/ROOT/anything.jsp" not found
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/bid/1531 http://www.iss.net/security_center/static/4967.php |
| ÇØ°áÃ¥ |
ÀÌ ¹®Á¦´Â Tomcat 3.2.1¿¡¼ ÇØ°áµÇ¾ú´Ù. Jakarta ProjectÀÇ À¥»çÀÌÆ®, http://jakarta.apache.org/ ¿¡¼ ¹öÀü 3.2.1À» ´Ù¿î·Îµå ¹Þ¾Æ ÀνºÅçÇØ¾ß ÇÑ´Ù. |
| °ü·Ã URL |
CVE-2000-0759 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|