English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22256
À§Çèµµ 30
Æ÷Æ® 7777, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Oracle HTTP ¼­¹öÀÇ iSQLplus¿¡´Â Cross-Site Scripting Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
ÀÌ Cross-Site Scripting Ãë¾àÁ¡Àº iSQLplus ½ºÅ©¸³Æ® »ó¿¡¼­ 'action', 'username', 'password' ÆÄ¶ó¹ÌÅÍ¿¡ ÀԷµǴ »ç¿ëÀÚ ÀԷµéÀÌ ÀûÀýÈ÷ ÇÊÅ͸µµÇÁö ¸øÇÏ´Â µ¥ ±× ¿øÀÎÀÌ ÀÖ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº ´ÙÀ½°ú °°ÀÌ iSQLplus ½ºÅ©¸³Æ®¿Í ¿¬°áµÈ ¾ÇÀÇÀûÀÎ URL ¸µÅ©¸¦ ¸¸µé°í »ç¿ëÀÚ°¡ ÀÌ ¸µÅ©¸¦ Ŭ¸¯Çϵµ·Ï À¯µµÇÒ ¼ö ÀÖ´Ù:

http://[target]/isqlplus?action=logon&username=sdfds%22%3e%3cscript%3ealert('XSS')%3c/script%3e\&password=dsfsd%3cscript%3ealert('XSS')%3c/script%3e

ÀÏ´Ü ¸µÅ©°¡ Ŭ¸¯µÇ¸é, ÀÓÀÇÀÇ Äڵ尡 ¿À¶óŬ ¼­¹öÀÇ ±ÇÇÑÀ¸·Î »ç¿ëÀÚÀÇ À¥ ºê¶ó¿ìÀú »ó¿¡¼­ ½ÇÇàµÈ´Ù. ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÔÀ¸·Î½á, °ø°ÝÀÚµéÀº »ç¿ëÀÚµéÀÇ ÄíŰ(Cookie) ±â¹ÝÀÇ ÀÎÁõ ½Å¿ëÁ¤º¸µéÀ» ȹµæÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securitytracker.com/alerts/2004/Jan/1008838.html
http://archives.neohapsis.com/archives/bugtraq/2004-01/0233.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Oracle HTTP Server 8.1.7
Oracle HTTP Server 9.0.1
Oracle HTTP Server 9.2.0
ÇØ°áÃ¥ 2014³â 6¿ù ÇöÀç ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡´Â ³ª¿Í ÀÖÁö ¾Ê´Ù.
°ü·Ã URL CVE-2004-2115 (CVE)
°ü·Ã URL 9484 (SecurityFocus)
°ü·Ã URL 14930 (ISS)