| Ãë¾àÁ¡ID |
22120 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
WWW |
| »ó¼¼¼³¸í |
Novell GroupWiseÀÇ GWWEB.EXE¿¡ ÀÖ´Â HELP ±â´ÉÀÌ ´Ù¼ö Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ´Ù. Novell GroupWise´Â Novell »ç·ÎºÎÅÍ ¹èÆ÷µÈ µð·ºÅ丮 ¼ºñ½º·Î ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® À©µµ¿ìÁî Ç÷§Æû¿¡¼ »ç¿ëÇÒ ¼ö ÀÖ´Ù. °¢Á¾ º¸°í¿¡ ÀÇÇÏ¸é ´ÙÀ½°ú °°Àº Ãë¾àÁ¡µéÀÌ GroupWise À¥ ÀÎÅÍÆäÀ̽º¿¡ Á¸ÀçÇÑ´Ù:
1. GWWEB.EXE¿¡ ÀÖ´Â HELP Àμö´Â ¼¹ö»óÀÇ ¿ÏÀüÇÑ À¥ °æ·Î¸íÀ» ³ëÃâ½Ã۴µ¥ »ç¿ëµÉ ¼ö ÀÖ´Ù. 2. ÀÓÀÇÀÇ »ç¿ëÀÚ°¡ GWWEB.EXE¿Í HELP Àμö·Î ½Ã½ºÅÛ»ó¿¡ Á¸ÀçÇÏ´Â .htm ÆÄÀÏÀ» ÀÐÀ» ¼ö ÀÖ´Ù.
¿¹: 1. http://server/cgi-bin/GW5/GWWEB.EXE?HELP=bad-request ¸¦ º¸³»¸é ¼¹ö´Â ´ÙÀ½°ú °°ÀÌ ÀÀ´äÇÑ´Ù: Could not find file SYS:WEB\CGI-BIN\GW5\US\HTML3\HELP\BAD-REQUEST.HTM
2. HELP¿Í ../ ¹®ÀÚ¿À» ÀÌ¿ëÇÏ¿© ¼¹ö»óÀÇ ÀÓÀÇÀÇ À§Ä¡¿¡ ÀÖ´Â .htm ÆÄÀϵéÀ» Àаųª µð·ºÅ丮¸¦ Ž»öÇÒ ¼ö ÀÖ´Ù: http ://server/cgi-bin/GW5/GWWEB.EXE?HELP=../../../secret.htm
* Âü°í »çÀÌÆ®: http://online.securityfocus.com/bid/879 http://www.securiteam.com/exploits/3I5QDQ0QAG.html
Ãë¾àÇÑ ½Ã½ºÅÛµé: GroupWise 5.2 GroupWise 5.5 |
| ÇØ°áÃ¥ |
GroupWiseÀÇ °¡Àå ÃֽйöÀü (GroupWise 6)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. http://www.novell.com/products/groupwise/ ¸¦ ÂüÁ¶Ç϶ó. |
| °ü·Ã URL |
CVE-1999-1005 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|