English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22111
À§Çèµµ 30
Æ÷Æ® 8080
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Servlet
»ó¼¼¼³¸í ÇØ´ç Apache Tomcat ¼­¹ö´Â /servlet/ ¸ÅÇο¡ ´ëÇÑ ¿äû¿¡ ÀÇÇÑ Cross Site Scripting °ø°Ýµé¿¡ Ãë¾àÇÏ´Ù.
Apache TomcatÀº Java Servlet°ú JavaServer Pages ±â¼úµéÀ» À§ÇÑ °ø½ÄÀûÀÎ ·¹ÆÛ·±½º ±¸Çö¿¡ »ç¿ëµÇ°í ÀÖ´Â Servlet Container ÀÌ´Ù.
´Ù¾çÇÑ ¼­ºí¸´µéÀÇ / Ŭ·¡½ºµéÀ» È£ÃâÇϱâ À§ÇÏ¿© /servlet/ ¸ÅÇÎÀ» »ç¿ë, TomcatÀÌ ¿¹¿Ü (exception)¸¦ ÀÏÀ¸Å°µµ·Ï(throw) ÇÒ ¼ö ÀÖÀ¸¸ç, ¿©±â¼­ TomcatÀº ´ÙÀ½°ú °°Àº Cross Site Scripting (XSS) °ø°ÝµéÀ» Çã¿ëÇÑ´Ù:

tomcat-server/servlet/org.apache.catalina.servlets.WebdavStatus/SCRIPTalert(document.domain)/SCRIPT
tomcat-server/servlet/org.apache.catalina.ContainerServlet/SCRIPTalert(document.domain)/SCRIPT
tomcat-server/servlet/org.apache.catalina.Context/SCRIPTalert(document.domain)/SCRIPT
tomcat-server/servlet/org.apache.catalina.Globals/SCRIPTalert(document.domain)/SCRIPT

(²©¼è(angle brackets)´Â »ý·«µÊ)

* Âü°í »çÀÌÆ®:
http://www.securiteam.com/windowsntfocus/5KP0L007FI.html
http://tomcat.apache.org/security-4.html

Ãë¾àÇÑ Ç÷§Æû:
* Apache Tomcat v4.0.3
* Windows NT/2000
* Linux
ÇØ°áÃ¥ web.xml ÆÄÀÏ¿¡ Á¤ÀǵÇÁö ¾ÊÀº À͸í(anonymous)ÀÇ ¼­ºí¸´ Ŭ·¡½ºµéÀ» ½ÇÇà½Ãų ¼ö ÀÖ´Â (/servlet/¿¡ ¸Ê µÈ) 'invoker' ¼­ºí¸´À» ¸ÅÇο¡¼­ Á¦°ÅÇØ¾ß ÇÑ´Ù.

¸ÅÇÎµÈ ¿£Æ®¸®´Â /tomcat-install-dir/conf/web.xml ÆÄÀÏ¿¡¼­ ãÀ» ¼ö ÀÖ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)