English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22120
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í Novell GroupWiseÀÇ GWWEB.EXE¿¡ ÀÖ´Â HELP ±â´ÉÀÌ ´Ù¼ö Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ´Ù.
Novell GroupWise´Â Novell »ç·ÎºÎÅÍ ¹èÆ÷µÈ µð·ºÅ丮 ¼­ºñ½º·Î ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® À©µµ¿ìÁî Ç÷§Æû¿¡¼­ »ç¿ëÇÒ ¼ö ÀÖ´Ù. °¢Á¾ º¸°í¿¡ ÀÇÇÏ¸é ´ÙÀ½°ú °°Àº Ãë¾àÁ¡µéÀÌ GroupWise À¥ ÀÎÅÍÆäÀ̽º¿¡ Á¸ÀçÇÑ´Ù:

1. GWWEB.EXE¿¡ ÀÖ´Â HELP Àμö´Â ¼­¹ö»óÀÇ ¿ÏÀüÇÑ À¥ °æ·Î¸íÀ» ³ëÃâ½Ã۴µ¥ »ç¿ëµÉ ¼ö ÀÖ´Ù.
2. ÀÓÀÇÀÇ »ç¿ëÀÚ°¡ GWWEB.EXE¿Í HELP Àμö·Î ½Ã½ºÅÛ»ó¿¡ Á¸ÀçÇÏ´Â .htm ÆÄÀÏÀ» ÀÐÀ» ¼ö ÀÖ´Ù.

¿¹:
1. http://server/cgi-bin/GW5/GWWEB.EXE?HELP=bad-request ¸¦ º¸³»¸é ¼­¹ö´Â ´ÙÀ½°ú °°ÀÌ ÀÀ´äÇÑ´Ù:
Could not find file SYS:WEB\CGI-BIN\GW5\US\HTML3\HELP\BAD-REQUEST.HTM

2. HELP¿Í ../ ¹®ÀÚ¿­À» ÀÌ¿ëÇÏ¿© ¼­¹ö»óÀÇ ÀÓÀÇÀÇ À§Ä¡¿¡ ÀÖ´Â .htm ÆÄÀϵéÀ» Àаųª µð·ºÅ丮¸¦ Ž»öÇÒ ¼ö ÀÖ´Ù:
http ://server/cgi-bin/GW5/GWWEB.EXE?HELP=../../../secret.htm

* Âü°í »çÀÌÆ®:
http://online.securityfocus.com/bid/879
http://www.securiteam.com/exploits/3I5QDQ0QAG.html

Ãë¾àÇÑ ½Ã½ºÅÛµé:
GroupWise 5.2
GroupWise 5.5
ÇØ°áÃ¥ GroupWiseÀÇ °¡Àå ÃֽйöÀü (GroupWise 6)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
http://www.novell.com/products/groupwise/ ¸¦ ÂüÁ¶Ç϶ó.
°ü·Ã URL CVE-1999-1005 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)