| Ãë¾àÁ¡ID |
22139 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
8888 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
WWW |
| »ó¼¼¼³¸í |
ÇØ´ç Sun AnswerBook2 dwhttpd´Â Àΰ¡µÇÁö ¾ÊÀº °ü¸®¿ë ½ºÅ©¸³Æ®¿¡ ´ëÇÑ ¾×¼¼½º¸¦ Çã¿ëÇÑ´Ù. Sun »çÀÇ AnswerBook2´Â »ç¿ëÀÚµéÀÌ À¥ ºê¶ó¿ìÁ ÀÌ¿ëÇÏ¿© Sun ¿Â¶óÀÎ ¹®¼¸¦ º¼ ¼ö ÀÖ°Ô ÇØ ÁÖ´Â À¯Æ¿¸®Æ¼ÀÌ´Ù. Inso DynaWeb À¥¼¹öÀÎ dwhttpd´Â Sun »çÀÇ AnswerBook2¿Í °°Àº Á¦Ç°µé¿¡¼ ºÎºÐÀûÀÎ ±¸¼º¿ä¼Ò·Î½á »ç¿ëµÈ´Ù. AnswerBook2´Â Solaris ¿î¿µÃ¼Á¦¿¡ ¼³Ä¡µÇ¾î °ø±ÞµÇ°í ÀÖ´Ù. AnswerBook2 1.2¿¡¼ 1.4.2 ¹öÀüµé¿¡ ÀÖ´Â ÀÎÁõü°èÀÇ °áÇÔ°ú °ü·ÃµÈ Ãë¾àÁ¡Àº ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ Àΰ¡µÇÁö ¾ÊÀº °ü¸®¿ë ½ºÅ©¸³Æ®µé·ÎÀÇ ¾×¼¼½º¸¦ Çã¿ëÇÑ´Ù. À̰ÍÀº °ø°ÝÀÚ°¡ »õ·Î¿î °ü¸®ÀÚ¸¦ Ãß°¡Çϰųª ¼¹öÀÇ ¿¡·¯·Î±×¸¦ º¸´Â °Í°ú °°Àº °ü¸®¿ëÀÇ ±â´ÉµéÀ» ¼öÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¿¹¸¦µé¾î, ´ÙÀ½ URLÀº ·ÎÄà AnswerBook2 ¼¹öÀÇ ¿¡·¯·Î±×¸¦ º¸¿© ÁÙ °ÍÀÌ´Ù:
http://localhost:8888/ab2/@AdminViewError
AdminAddadmin (»ç¿ëÀÚ¸í 'foo' ÆÐ½º¿öµå 'bar'¸¦ Ãß°¡)¸¦ Æ÷ÇÔÇÏ¿© °ø°ÝÀÚ°¡ µµ¿ëÇÒ ¼ö ÀÖ´Â ¸¹Àº ½ºÅ©¸³Æ®µéÀÌ ÀÖ´Ù:
http://localhost:8888/ab2/@AdminAddadmin?uid=foo&password=bar&re_password=bar
* Ãë¾àÇÑ Ç÷§Æû: Sun AnswerBook2 1.2 Sun AnswerBook2 1.3 Sun AnswerBook2 1.4 Sun AnswerBook2 1.4.1 Sun AnswerBook2 1.4.2 |
| ÇØ°áÃ¥ |
Vender¿Í »óÀÇÇÏ¿© AnswerBook2 ÆÐÄ¡¸¦ ±¸ÇÏ¿© ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù:
AnswerBook 1.4.2: 110531-01 ÆÐÄ¡ Àû¿ë. AnswerBook 1.4.2_x86: 110537-01 ÆÐÄ¡ Àû¿ë. AnswerBook 1.4.3: 110532-01 ÆÐÄ¡ Àû¿ë. AnswerBook 1.4.3_x86: 110538-01 ÆÐÄ¡ Àû¿ë.
ÇÊ¿äÇÏÁö ¾Ê´Ù¸é AnswerBook2 ¼³ºñ¸¦ ÀÛµ¿ÁßÁö ½ÃÄÑ¾ß ÇÑ´Ù. ÀÛµ¿ÁßÁö ½Ã۱â À§Çؼ´Â: 1. dwhttpd ´ë¸óÀ» ´ÙÀ½°ú °°ÀÌ Kill ½ÃŲ´Ù. # /etc/init.d/ab2mgr stop 2. ´ÙÀ½°ú °°ÀÌ ºÎÆÃ ½ºÅ©¸³Æ®·ÎºÎÅÍ ½ÃÀÛÇÏÁö ¾Êµµ·Ï RC ½ºÅ©¸³Æ® ÆÄÀϸíÀ» º¯°æÇÑ´Ù: # mv /etc/rc2.d/S96ab2mgr /etc/rc2.d/s96ab2mgr |
| °ü·Ã URL |
CVE-2002-2425 (CVE) |
| °ü·Ã URL |
5383 (SecurityFocus) |
| °ü·Ã URL |
9756 (ISS) |
|