Ãë¾àÁ¡ID |
23209 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
Daemon |
»ó¼¼¼³¸í |
ÇØ´ç HP OpenView NNMÀº ÀÓÀÇÀÇ ¸í·É ¼öÇàÀ» Çã¿ëÇÏ´Â ´ÙÁßÀÇ CGI ½ºÅ©¸³Æ®µéÀ» Æ÷ÇÔÇÏ°í ÀÖ´Ù. HP OpenView Network Node Manager (NNM)´Â ³×Æ®¿öÅ© »óÀÇ ÀåºñµéÀ» ¹ß°ßÇÏ°í ½ÇÁ¦·Î ¾î¶»°Ô ³×Æ®¿öÅ©°¡ Çü¼ºµÇ¾î ÀÖ´Â Áö¸¦ ¾È³»ÇØ ÁÖ´Â Áöµµ¸¦ Á¦°øÇØ ÁØ´Ù. HP OpenView Network Node Manager (OV NNM) 7.51, ±×¸®°í 7.53 ¹öÀüµéÀº 'OpenView5.exe' CGI ½ºÅ©¸³Æ®ÀÇ 'Action' Àμö·Î Àü´ÞµÈ »ç¿ëÀÚ°¡ Á¦°øÇÑ ÀԷ¿¡ ´ëÇÑ ºÎÀûÀýÇÑ °ËÁõÀ¸·Î ÀÎÇÏ¿©, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ½Ã½ºÅÛ »óÀÇ µð·ºÅ丮µéÀ» Ž»öÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. Action Àμö¿¡ "dot dot" ½ÃÄö½ºµé(/../)À» Æ÷ÇÔÇÏ´Â OpenView5.exe CGI ¾îÇø®ÄÉÀ̼ÇÀ¸·ÎÀÇ Àß Á¶ÀÛµÈ URL ¿äûÀ» º¸³¿À¸·Î½á, °ø°ÝÀÚ´Â µð·ºÅ丮µéÀ» Ž»öÇÏ¿© ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡ ÀÖ´Â ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐ¾î ³¾ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://aluigi.altervista.org/adv/closedviewx-adv.txt http://www.securityfocus.com/archive/1/490771/30/0/threaded http://secunia.com/secunia_research/2008-4/advisory/ http://www.securityfocus.com/archive/1/490834/30/0/threaded http://securitytracker.com/alerts/2008/Apr/1019838.html http://secunia.com/advisories/29796
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: HP OpenView Network Node Manager 7.51, 7.53 Microsoft Windows Any version |
ÇØ°áÃ¥ |
´ÙÀ½ À¥»çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ÀûÀýÇÑ ÆÐÄ¡(NNM_01168 ¶Ç´Â NNM_01159)¸¦ ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù. http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01496048 |
°ü·Ã URL |
CVE-2008-0068 (CVE) |
°ü·Ã URL |
28745 (SecurityFocus) |
°ü·Ã URL |
41790 (ISS) |
|