Ãë¾àÁ¡ID |
28140 |
À§Çèµµ |
30 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMB |
»ó¼¼¼³¸í |
Commerce Server 2002ÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é ÇØ´ç ¼¹ö¿¡´Â ÀÎÁõ ¿ìȸ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Microsoft Commerce Server´Â ÀüÀÚ »ó°Å·¡ »çÀÌÆ®µéÀ» ¸¸µé°í ¹èÄ¡ÇÏ°í ºÐ¼®ÇÏ´Â µ¥ »ç¿ëµÇ´Â À¥ ¼¹ö Á¦Ç°ÀÌ´Ù. SP2 ÀÌÀüÀÇ Microsoft Commerce Server 2002´Â ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ authfiles µð·ºÅ丮¿¡ ÀÖ´Â ¿¹Á¦ ASP ÆÄÀϵéÀ» ÀÌ¿ëÇÏ¿© ÀÎÁõÀ» ¿ìȸÇÏ°í Æнº¿öµå¸¦ ¸ð¸£´Â Á¤»ó »ç¿ëÀڷμ ·Î±×¿Â ÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¸¸¾à °ø°ÝÀÚ°¡ Á¤»ó »ç¿ëÀÚ¸íÀ» ¾Ë°í ÀÖ´Ù¸é ±× °ø°ÝÀÚ´Â Á¤»ó »ç¿ëÀÚ¸í°ú ÀÓÀÇÀÇ Æнº¿öµå¸¦ °¡Áö°í authfiles/login.asp·Î ·Î±×ÀÎÀ» ½ÃµµÇÑ ÈÄ ¸ÞÀÎ »çÀÌÆ®¿¡ µÎ ¹ø Á¢¼ÓÇÔÀ¸·Î½á ÀÎÁõÀ» ¿ìȸÇÏ°í ºñÀΰ¡µÈ ¾×¼¼½º¸¦ ¾ò¾î³¾ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®ÀÇ ·¹Áö½ºÆ®¸®¸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/archive/1/archive/1/427974/100/0/threaded http://secunia.com/advisories/9176 http://www.osvdb.org/24121
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Microsoft Commerce Server 2002 Microsoft Commerce Server 2002 SP1 Microsoft Windows Any version |
ÇØ°áÃ¥ |
Microsoft Commerce Server 2002´Â ´õ ÀÌ»ó Áö¿øµÇÁö ¾Ê´Â´Ù. ÃֽŠ¹öÀüÀÇ Microsoft Commerce Server·Î ¾÷±×·¹À̵å ÇÒ °ÍÀ» ±Ç°íÇÑ´Ù. |
°ü·Ã URL |
CVE-2006-1257 (CVE) |
°ü·Ã URL |
17134 (SecurityFocus) |
°ü·Ã URL |
25330 (ISS) |
|