Ãë¾àÁ¡ID |
22444 |
À§Çèµµ |
30 |
Æ÷Æ® |
8080, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
Servlet |
»ó¼¼¼³¸í |
ÇØ´ç Caucho Resin ¼¹ö´Â °¨ÃçÁø WEB-INF µð·ºÅ丮 Ž»ö °ø°Ý¿¡ Ãë¾àÇÏ´Ù. Caucho Resin´Â ¼ºí¸´/JSP ¼¹öÀÌ´Ù. Caucho Resin ¹öÀü 3.1.0°ú ±× ÀÌÀüÀÇ ¹öÀüµéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¿µÇâÀ» ¹Þ´Â È£½ºÆ® »ó¿¡ ÀÖ´Â ÀÓÀÇÀÇ ÆÄÀϵéÀ» º¼ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. °ø¹é¹®ÀÚ(%20)¸¦ ÀÎÄÚµùÇÑ URLÀ» Æ÷ÇÔÇÑ Àß Á¶ÀÛµÈ URLÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â °¨ÃçÁø WEB-INF µð·ºÅ丮¸¦ Ž»öÇÏ¿© ¿µÇâÀ» ¹Þ´Â È£½ºÆ® »óÀÇ ¾î¶² ÆÄÀÏÀ» º¼ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.caucho.com/resin-3.1/changes/changes.xtp http://securitytracker.com/alerts/2007/May/1018061.html http://secunia.com/advisories/25286
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Caucho Technology »ç, Resin ¹öÀü 3.1.0°ú ±× ÀÌÀüÀÇ ¹öÀüµé Microsoft Windows Any version |
ÇØ°áÃ¥ |
Caucho Technology ´Ù¿î·Îµå À¥ »çÀÌÆ®ÀÎ http://caucho.com/products/resin/download ¿¡¼ Caucho ResinÀÇ °¡Àå ÃֽŠ¹öÀü (3.1.1 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2007-2440 (CVE) |
°ü·Ã URL |
23985 (SecurityFocus) |
°ü·Ã URL |
34296 (ISS) |
|