English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22112
À§Çèµµ 30
Æ÷Æ® 8080
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Servlet
»ó¼¼¼³¸í ÇØ´ç Tomcat ÀÚ¹Ù ¼­¹ö´Â À§ÇèÇÑ ¿¹Á¦ ¼Ò½ºµéÀ» °¡Áö°í ÀÖ´Ù.
TomcatÀº °ø°³¿ë ÀÚ¹Ù ¼­¹öÀÌ´Ù. ¿©·¯ °¡Áö µð·ºÅ丮 ¸®½ºÆÃ°ú À¥ ·çÆ®(root) À§Ä¡ ³ëÃâ Ãë¾àÁ¡ÀÌ ÀÌ Á¦Ç°¿¡¼­ ¹ß°ßµÇ¾ú´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ´ë»ó È£½ºÆ®¿¡ ´ëÇÑ ºñ°ø°³ Á¤º¸µéÀ» º¼ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù.
'/examples/jsp/source.jsp' ÆÄÀÏÀº Á¤»óÀûÀ¸·Î ¿¹Á¦ µð·ºÅ丮³»¿¡ ÇÁ·Î±×·¥ÀÇ ¼Ò½ºÄڵ带 º¸´Âµ¥ »ç¿ëµÈ´Ù. ±×¸®°í '/test/realPath.jsp' ÆÄÀÏÀº À¥ rootÀÇ À§Ä¡¸¦ ¾Ë·ÁÁØ´Ù.

´ÙÀ½ URLÀ» ¿äûÇÔÀ¸·Î½á Ãë¾àÁ¡À» µµ¿ëÇÒ ¼ö ÀÖ´Ù:
http://webserver:80/examples/jsp/source.jsp??
http://webserver:80/examples/jsp/source.jsp?/jsp/

Ãë¾àÇÑ Ç÷§Æû:
* Apache Tomcat Java ¼­¹ö ¹öÀü 3.23 ±×¸®°í 3.24
ÇØ°áÃ¥ ÇÊ¿äÇÏÁö ¾Ê´Ù¸é ¿¹Á¦ µð·ºÅ丮¸¦ »èÁ¦ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2002-2007 (CVE)
°ü·Ã URL 4876,4877,4878 (SecurityFocus)
°ü·Ã URL 9208 (ISS)