| Ãë¾àÁ¡ID |
22256 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
7777, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
WWW |
| »ó¼¼¼³¸í |
ÇØ´ç Oracle HTTP ¼¹öÀÇ iSQLplus¿¡´Â Cross-Site Scripting Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ÀÌ Cross-Site Scripting Ãë¾àÁ¡Àº iSQLplus ½ºÅ©¸³Æ® »ó¿¡¼ 'action', 'username', 'password' ÆÄ¶ó¹ÌÅÍ¿¡ ÀԷµǴ »ç¿ëÀÚ ÀԷµéÀÌ ÀûÀýÈ÷ ÇÊÅ͸µµÇÁö ¸øÇÏ´Â µ¥ ±× ¿øÀÎÀÌ ÀÖ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº ´ÙÀ½°ú °°ÀÌ iSQLplus ½ºÅ©¸³Æ®¿Í ¿¬°áµÈ ¾ÇÀÇÀûÀÎ URL ¸µÅ©¸¦ ¸¸µé°í »ç¿ëÀÚ°¡ ÀÌ ¸µÅ©¸¦ Ŭ¸¯Çϵµ·Ï À¯µµÇÒ ¼ö ÀÖ´Ù:
http://[target]/isqlplus?action=logon&username=sdfds%22%3e%3cscript%3ealert('XSS')%3c/script%3e\&password=dsfsd%3cscript%3ealert('XSS')%3c/script%3e
ÀÏ´Ü ¸µÅ©°¡ Ŭ¸¯µÇ¸é, ÀÓÀÇÀÇ Äڵ尡 ¿À¶óŬ ¼¹öÀÇ ±ÇÇÑÀ¸·Î »ç¿ëÀÚÀÇ À¥ ºê¶ó¿ìÀú »ó¿¡¼ ½ÇÇàµÈ´Ù. ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÔÀ¸·Î½á, °ø°ÝÀÚµéÀº »ç¿ëÀÚµéÀÇ ÄíŰ(Cookie) ±â¹ÝÀÇ ÀÎÁõ ½Å¿ëÁ¤º¸µéÀ» ȹµæÇÒ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securitytracker.com/alerts/2004/Jan/1008838.html http://archives.neohapsis.com/archives/bugtraq/2004-01/0233.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Oracle HTTP Server 8.1.7 Oracle HTTP Server 9.0.1 Oracle HTTP Server 9.2.0 |
| ÇØ°áÃ¥ |
2014³â 6¿ù ÇöÀç ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡´Â ³ª¿Í ÀÖÁö ¾Ê´Ù. |
| °ü·Ã URL |
CVE-2004-2115 (CVE) |
| °ü·Ã URL |
9484 (SecurityFocus) |
| °ü·Ã URL |
14930 (ISS) |
|