English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23066
À§Çèµµ 30
Æ÷Æ® 6680
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù LDAP
»ó¼¼¼³¸í ÇØ´ç SurgeLDAP ¼­¹ö¿¡´Â "dot dot" ½ÃÄö½º¸¦ ÀÌ¿ëÇÑ µð·ºÅ丮 Ž»ö Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
SurgeLDAPÀº Microsoft Windows ¿Í Linux °è¿­ÀÇ ¿î¿µÃ¼Á¦ »ó¿¡¼­ µ¿ÀÛÇÏ´Â Lightweight Directory Access Protocol (LDAP) v3 ¼­¹öÀÌ´Ù. SurgeLDAP ¼­¹öÀÇ ÀϺΠ¹öÀü¿¡´Â "user.cgi" ½ºÅ©¸³Æ®»ó¿¡¼­ »ç¿ëÀÚ ÀÔ·ÂÀ» ÀûÀýÈ÷ ÇÊÅ͸µÇÏÁö ¸øÇÔÀ¸·Î ÀÎÇØ ½Ã½ºÅÛ »óÀÇ ÀÓÀÇÀÇ µð·ºÅ丮µéÀ» Ž»öÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. °ø°ÝÀÚµéÀº ´ÙÀ½°ú °°ÀÌ "user.cgi" ½ºÅ©¸³Æ®ÀÇ "page" ÆÄ¶ó¹ÌÅÍ¿¡ "dot dot" (../) ½ÃÄö½º(sequence)¸¦ Æ÷ÇÔÇÏ´Â Àß Á¶ÀÛµÈ URLÀ» ¼­¹ö¿¡ Àü´ÞÇÔÀ¸·Î½á, À¥ ·çÆ® ¿ÜºÎ¿¡ Á¸ÀçÇÏ´Â ½Ã½ºÅÛ »óÀÇ ÀÓÀÇÀÇ µð·ºÅ丮¸¦ Ž»öÇϰųª ÆÄÀϵéÀ» º¼ ¼ö ÀÖ´Ù.

http://[host]:6680/user.cgi?cmd=show&page=/../../../boot.ini


* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
NetWin SurgeLDAP 1.0g
NetWin SurgeLDAP 1.0e
NetWin SurgeLDAP 1.0d
Linux Any version
Windows Any version
ÇØ°áÃ¥ ÇØ´ç SurgeLDAP ¼­¹ö¿¡´Â "dot dot" ½ÃÄö½º¸¦ ÀÌ¿ëÇÑ µð·ºÅ丮 Ž»ö Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
SurgeLDAPÀº Microsoft Windows ¿Í Linux °è¿­ÀÇ ¿î¿µÃ¼Á¦ »ó¿¡¼­ µ¿ÀÛÇÏ´Â Lightweight Directory Access Protocol (LDAP) v3 ¼­¹öÀÌ´Ù. SurgeLDAP ¼­¹öÀÇ ÀϺΠ¹öÀü¿¡´Â "user.cgi" ½ºÅ©¸³Æ®»ó¿¡¼­ »ç¿ëÀÚ ÀÔ·ÂÀ» ÀûÀýÈ÷ ÇÊÅ͸µÇÏÁö ¸øÇÔÀ¸·Î ÀÎÇØ ½Ã½ºÅÛ »óÀÇ ÀÓÀÇÀÇ µð·ºÅ丮µéÀ» Ž»öÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. °ø°ÝÀÚµéÀº ´ÙÀ½°ú °°ÀÌ "user.cgi" ½ºÅ©¸³Æ®ÀÇ "page" ÆÄ¶ó¹ÌÅÍ¿¡ "dot dot" (../) ½ÃÄö½º(sequence)¸¦ Æ÷ÇÔÇÏ´Â Àß Á¶ÀÛµÈ URLÀ» ¼­¹ö¿¡ Àü´ÞÇÔÀ¸·Î½á, À¥ ·çÆ® ¿ÜºÎ¿¡ Á¸ÀçÇÏ´Â ½Ã½ºÅÛ »óÀÇ ÀÓÀÇÀÇ µð·ºÅ丮¸¦ Ž»öÇϰųª ÆÄÀϵéÀ» º¼ ¼ö ÀÖ´Ù.

http://[host]:6680/user.cgi?cmd=show&page=/../../../boot.ini


* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
NetWin SurgeLDAP 1.0g
NetWin SurgeLDAP 1.0e
NetWin SurgeLDAP 1.0d
Linux Any version
Windows Any version
°ü·Ã URL CVE-2004-2253 (CVE)
°ü·Ã URL 10103 (SecurityFocus)
°ü·Ã URL 15851 (ISS)