| Ãë¾àÁ¡ID |
22160 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
8080 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
Servlet |
| »ó¼¼¼³¸í |
ÇØ´ç Apache Tomcat ¼¹ö´Â Default ServletÀ» ÅëÇÑ JSP ¼Ò½º ³ëÃâ Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Jakarta TomcatÀº JavaServer Pages (JSP) ¿Í Java servlet µéÀ» Áö¿øÇÏ´Â Apache HTTP ¼¹öµé°ú ÇÔ²² »ç¿ëµÇ´Â Java ¾îÇø®ÄÉÀÌ¼Ç ¼¹öÀÌ´Ù. Tomcat 4.0.4¿Í 4.1.10 (¶Ç´Â ÀÌÇÏ) ¹öÀüµéÀº Default ServletÀÎ org.apache.catalina.servlets.DefaultServletÀ» »ç¿ëÇÑ ¼Ò½ºÄÚµå ³ëÃâ¿¡ Ãë¾àÇÏ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¾Ë·ÁÁø JSP ÆäÀÌÁöµé¿¡ ´ëÇÑ º¸È£ÀåÄ¡¸¦ ¿ìȸÇÒ ¼ö ÀÖ´Â Àß Á¶ÀÛµÈ URL ¿äûÀ» º¸³», ¿äûÇÑ JSP ÆÐÀÌÁöÀÇ ¼Ò½ºÄڵ带 ¾ò¾î³¾ ¼ö ÀÖ´Ù. ÀÌ ¼Ò½ºÄڵ忡´Â µ¥ÀÌÅͺ£À̽º ÆÐ½º¿öµå¿Í ÆÄÀϸíµéÀÌ Æ÷ÇԵǾî ÀÖÀ» ¼ö ÀÖ´Ù.
¿¹¸¦µé¾î, Tomcat 4.1.10 admin ¾îÇø®ÄÉÀ̼ÇÀÎ: http://localhost:8080/admin/index.jsp ÀÇ JSP ¼Ò½º¸¦ º¸±â À§Çؼ´Â ´ÙÀ½°ú °°ÀÌ ÇÒ ¼ö ÀÖ´Ù: http://localhost:8080/admin/servlet/org.apache.catalina.servlets.DefaultServlet/index.jsp
* Âü°í »çÀÌÆ®: http://online.securityfocus.com/bid/5786 http://www.iss.net/security_center/static/10175.php
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Tomcat ¹öÀü 4.0.4 ÀÌÇÏ Tomcat ¹öÀü 4.1.10 ÀÌÇÏ Windows Ç÷§Æû UNIX/Linux Ç÷§Æû |
| ÇØ°áÃ¥ |
´ÙÀ½ À¥ »çÀÌÆ®·ÎºÎÅÍ Apache TomcatÀÇ °¡Àå ÃֽЏ±¸®Á ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://tomcat.apache.org/ |
| °ü·Ã URL |
CVE-2002-1148 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|