English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22094
À§Çèµµ 20
Æ÷Æ® 8000, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Servlet
»ó¼¼¼³¸í ÇØ´ç Allaire JRun ¼­¹ö´Â º¸¾È»ó Áß¿äÇÑ °æ·Î¸í Á¤º¸¸¦ ³ëÃâ½ÃŲ´Ù. JRunÀº JSP¿Í ÀÚ¹Ù ¼­ºí¸´°ú ÇÔ²² À¥ ÀÀ¿ëÇÁ·Î±×·¥À» °³¹ßÇϴµ¥ »ç¿ëµÈ´Ù.
»ç¿ëÀÚ°¡ Á¸ÀçÇÏÁö ¾Ê´Â JSP ÆÄÀÏÀÇ URLÀ» ¿äûÇÒ ¶§, À¥ µð·ºÅ丮·ÎÀÇ ¹°¸®Àû °æ·Î¸íÀÌ ¿¡·¯ ¸Þ½ÃÁöÀÇ ÇÑ ºÎºÐÀ¸·Î½á ¼­¹ö¿¡ ÀÇÇØ Á¦°øµÈ´Ù. ÀÌ ¹æ¹ýÀÌ Attacker¿¡°Ô´Â °ø°Ý¿¡ µµ¿òÀÌ µÇ´Â À¥¼­¹öÀÇ ÆÄÀÏ ±¸Á¶¿¡ ´ëÇÑ Á¤º¸¸¦ ¾ò´Âµ¥ »ç¿ëµÉ ¼ö ÀÖ´Ù.
´ÙÀ½°ú °°Àº ¿äû¿¡ ÀÇÇØ À¥ µð·ºÅ丮·ÎÀÇ °æ·Î¸íÀ» º¼ ¼ö ÀÖ´Ù: http://www.example.com:8000/anything.jsp

500 Internal Server Error

Could not find JSP/JHTML source or class files: C:\JRun\jsm-default\services\jws\htdocs\anything0.jsp

* Âü°í »çÀÌÆ®:
http://online.securityfocus.com/bid/1531
http://www.securityfocus.com/bid/3592

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Allaire JRun ¼­¹ö
ÇØ°áÃ¥ ´ÙÀ½ »çÀÌÆ®·ÎºÎÅÍ Adobe JRunÀÇ °¡Àå ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵åÇÑ´Ù:
https://www.adobe.com/products/jrun/download/
°ü·Ã URL CVE-2001-1510 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)