English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22093
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Servlet
»ó¼¼¼³¸í ÇØ´ç Java servlet container´Â cross-site scripting °ø°Ý¿¡ Ãë¾àÇÏ´Ù.
ÇØ´ç Java servlet container´Â ¼­¹öÀÇ À¥»çÀÌÆ® »ó¿¡ ¿Ã¶ó¿Í ÀÖ´Â »ç¿ëÀÚ ÀÔ·Â ¸µÅ©¿¡ Æ÷ÇÔµÈ ½ºÅ©¸³Æ®µéÀ» ÇÊÅÍÇÏÁö ¾Ê´Â´Ù. ¾ÇÀÇÀûÀÎ À¥ °ü¸®ÀÚ´Â ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© hyper-link¸¦ Ŭ¸¯ÇÑ »ç¿ëÀÚ°¡ JavaScript ¸í·ÉµéÀ̳ª ³»ÀåµÈ ½ºÅ©¸³Æ® µéÀÌ ½ÇÇàµÇ°Ô ÇÒ ¼ö ÀÖ´Ù. ¾ÇÀÇÀûÀÎ hyper-link°¡ Ŭ¸¯µÇ¸é, À¥¼­¹ö¿¡ ´ëÇÑ Ç¥ÁØ ¿¡·¯ ¸Þ½ÃÁö°¡ Ãâ·ÂµÇ¸ç, µ¿ÀÏÇÑ ºê¶ó¿ìÀú¸¦ »ç¿ëÁßÀÎ µµ¸ÞÀγ» ¼­¹öµé¿¡ ÀÖ´Â ÀÓÀÇÀÇ ÄÚµå±îÁö ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

´ÙÀ½ µÎ°¡Áö Á¶°ÇÀÌ ÃæÁ·µÉ ¶§ ÀÌ ¹®Á¦Á¡ÀÌ ÃÊ·¡µÉ ¼ö ÀÖ´Ù:
- ºê¶ó¿ìÀú·Î ºÎÅÍ ÀÔ·ÂµÈ µ¥ÀÌŸ°¡ µ¿ÀûÀ¸·Î »ý¼ºµÇ¾î ºê¶ó¿ìÀú·Î µÇº¸³»Áø HTML ÆäÀÌÁöÀÇ ºÎºÐÀ¸·Î½á Àç»ç¿ëµÇ±â Àü¿¡ ÀûÀýÇÏ°Ô Å¸´ç¼º °Ë»ç¸¦ ÇÏÁö ¾Ê´Â´Ù.
- À¥ °³¹ßÀÚµéÀº µ¿Àû HTML ÆäÀÌÁö¸¦ »ý¼ºÇÏ´Â µ¥¿¡ »ç¿ëµÇ´Â ºê¶ó¿ìÀú·Î ºÎÅÍ ÀÔ·ÂµÈ µ¥ÀÌŸ¸¦ ±×´ë·Î ÀúÀåÇÑ´Ù.

Ãë¾àÇÑ ½Ã½ºÅÛµé:
* Tomcat versions 3.2.1, 3.2.2-beta, 4.0-beta
* JRun versions 2.3.3 and 3.0
* WebSphere versions 3.5 FP2, 3.02 and VisualAge for Java 3.5 Professional
* Resin version 1.2.2

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/6793.php
http://www.kb.cert.org/vuls/id/654643
ÇØ°áÃ¥ Jrun:
´ÙÀ½ »çÀÌÆ®·Î ºÎÅÍ ÃÖ½ÅÀÇ JrunÀ» ¼³Ä¡ÇÑ´Ù.
https://www.adobe.com/products/jrun/download/

WebSphere:
IBM »çÀÌÆ®¿¡¼­ ÃÖ½ÅÀÇ WebSphere¸¦ ¼³Ä¡ÇÑ´Ù.

±âŸ Á¶Ä¡¹æ¹ý:
404 ¿¡·¯ ÆäÀÌÁö¿¡¼­´Â ¹Ì¸® ÁöÁ¤ÇØ ³õÀº(static) Á¤º¸¸¦ º¸¿©ÁÖµµ·Ï ¼³Á¤ÇÑ´Ù.
°ü·Ã URL CVE-2001-1544 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)