{"id":22956,"date":"2025-11-21T09:00:44","date_gmt":"2025-11-21T00:00:44","guid":{"rendered":"https:\/\/blog.agentsoft.co.kr\/index.php\/2025\/11\/21\/22956\/"},"modified":"2025-11-21T09:00:44","modified_gmt":"2025-11-21T00:00:44","slug":"%ec%86%8c%ed%94%84%ed%8a%b8%ec%9b%a8%ec%96%b4-%eb%b3%b4%ec%95%88-cwe-top-25-%eb%b3%b4%ec%95%88-%ec%95%bd%ec%a0%90-%ea%b3%bc%ec%a0%9c","status":"publish","type":"post","link":"https:\/\/blog.agentsoft.co.kr\/index.php\/2025\/11\/21\/22956\/","title":{"rendered":"\uc18c\ud504\ud2b8\uc6e8\uc5b4 \ubcf4\uc548 CWE Top 25 \ubcf4\uc548 \uc57d\uc810 \uacfc\uc81c"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/image4.happycampus.com\/Production\/thumb212\/2024\/03\/15\/data29543483-0001.jpg\"><img decoding=\"async\" src=\"https:\/\/image4.happycampus.com\/Production\/thumb212\/2024\/03\/15\/data29543483-0002.jpg\"><\/p>\n<p><strong>\ubaa9\ucc28<\/strong><\/p>\n<p>1. Use After Free(UAF) : 416<br \/>\n1) UAF : \ud574\uc81c\ub41c \uba54\ubaa8\ub9ac \uc601\uc5ed\uc744 \uc7ac\uc0ac\uc6a9\ud560 \ub54c \ubc1c\uc0dd\ud558\ub294 \ubcf4\uc548 \uc57d\uc810<br \/>\n2) UAF \uacf5\uaca9\uc774 \ubc1c\uc0dd\ud560 \ub54c\uc758 \ubb38\uc81c\uc810<br \/>\n3) \uc608\uc2dc \ucf54\ub4dc<\/p>\n<p>2. SSRF(Cross-Site Request Forgery) : 918<br \/>\n1) SSRF<br \/>\n2) SSRF \uacf5\uaca9\uc774 \ubc1c\uc0dd\ud560 \ub54c\uc758 \ubb38\uc81c\uc810<br \/>\n3) \u2018\uce90\ud53c\ud0c8 \uc6d0\u2019<\/p>\n<p>3. OS Command Injection : 78<br \/>\n1) OS Command Injection<br \/>\n2) OS Command Injection\uc774 \ubc1c\uc0dd\ud560 \ub54c\uc758 \ubb38\uc81c\uc810<br \/>\n3) php \ucf54\ub4dc \uc608\uc2dc<\/p>\n<p><strong>\ubcf8\ubb38\ub0b4\uc6a9<\/strong><\/p>\n<p>1) UAF : \ud574\uc81c\ub41c \uba54\ubaa8\ub9ac \uc601\uc5ed\uc744 \uc7ac\uc0ac\uc6a9\ud560 \ub54c \ubc1c\uc0dd\ud558\ub294 \ubcf4\uc548 \uc57d\uc810<br \/>\nHeap \uc601\uc5ed(\uac1c\ubc1c\uc790\uac00 \ub3d9\uc801\uc73c\ub85c \uba54\ubaa8\ub9ac\ub97c \ud560\ub2f9\ud558\uc5ec \uc0ac\uc6a9\ud558\ub294 \uacf5\uac04)\uc5d0\uc11c \uc77c\uc5b4\ub098\ub294 \ubb38\uc81c \ub85c, Heap \ub0b4\uc5d0 \ud574\uc81c\ub41c \uba54\ubaa8\ub9ac \uacf5\uac04\uc774 \uc0c8\ub85c\uc6b4 \ud3ec\uc778\ud130\uc5d0 \ud560\ub2f9\ub420 \uacbd\uc6b0 \uadf8 \ud3ec\uc778\ud130\uac00 \uc601 \uc5ed \ub0b4\uc5d0 \uac12\uacfc \uc8fc\uc18c \uac12\uc744 \uc0ac\uc6a9\ud560 \uc218 \uc788\uac8c \ub418\uc5b4 \ubc1c\uc0dd\ud55c\ub2e4.<\/p>\n<p>2) UAF \uacf5\uaca9\uc774 \ubc1c\uc0dd\ud560 \ub54c\uc758 \ubb38\uc81c\uc810<br \/>\n\uc784\uc758\uc758 \uba54\ubaa8\ub9ac\uac00 \ud560\ub2f9\ub41c \ud3ec\uc778\ud130\uac00 \uc788\ub2e4\uace0 \uac00\uc815\ud558\uace0, \ud574\ub2f9 \ud3ec\uc778\ud130\uac00 free\ub97c \ud558\uba74 \ud560\ub2f9 \ub41c \uba54\ubaa8\ub9ac \ud560\ub2f9\uc740 \ud574\uc81c\ub41c\ub2e4. \ud558\uc9c0\ub9cc \ud574\uc81c\ub41c \ud6c4 \ub2e4\ub978 \ud3ec\uc778\ud130\uac00 \uac19\uc740 \uba54\ubaa8\ub9ac \ud06c\uae30\uc758 \uc601 \uc5ed\uc744 \ud560\ub2f9\ubc1b\ub294\ub2e4\uace0 \ud560 \ub54c, Heap\uc740 \ud574\uc81c\ub418\uc5c8\ub358 \uba54\ubaa8\ub9ac \uc601\uc5ed\uc744 \ud560\ub2f9\ud560 \uc218 \uc788\ub2e4. \uc774\ub54c \uc0c8\ub85c\uc6b4 \ud3ec\uc778\ud130\ub294 \uc774\uc804\uc5d0 \uc800\uc7a5\ub418\uc5c8\ub358 \uc8fc\uc18c\uc640 \uac12\uc744 \ucc38\uc870\ud560 \uc218 \uc788\ub2e4.<\/p>\n<p>\ucd9c\ucc98 : <a href=\"https:\/\/www.happycampus.com\/report-doc\/29543483\/\" target=\"_blank\">\ud574\ud53c\ucea0\ud37c\uc2a4<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\ubaa9\ucc28 1. Use After Free(UAF) : 416 1) UAF : \ud574\uc81c\ub41c \uba54\ubaa8\ub9ac \uc601\uc5ed\uc744 \uc7ac\uc0ac\uc6a9\ud560 \ub54c \ubc1c\uc0dd\ud558\ub294 \ubcf4\uc548 \uc57d\uc810 2) UAF \uacf5\uaca9\uc774 \ubc1c\uc0dd\ud560 \ub54c\uc758 \ubb38\uc81c\uc810 3) \uc608\uc2dc \ucf54\ub4dc 2. SSRF(Cross-Site Request Forgery) : 918 1) SSRF 2) SSRF \uacf5\uaca9\uc774 \ubc1c\uc0dd\ud560 \ub54c\uc758 \ubb38\uc81c\uc810 3) \u2018\uce90\ud53c\ud0c8 \uc6d0\u2019 3. OS Command Injection : 78 1) OS Command Injection 2) [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[28337,28336,28335],"class_list":["post-22956","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-cwe","tag-28336","tag-28335"],"_links":{"self":[{"href":"https:\/\/blog.agentsoft.co.kr\/index.php\/wp-json\/wp\/v2\/posts\/22956","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.agentsoft.co.kr\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.agentsoft.co.kr\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.agentsoft.co.kr\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.agentsoft.co.kr\/index.php\/wp-json\/wp\/v2\/comments?post=22956"}],"version-history":[{"count":0,"href":"https:\/\/blog.agentsoft.co.kr\/index.php\/wp-json\/wp\/v2\/posts\/22956\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.agentsoft.co.kr\/index.php\/wp-json\/wp\/v2\/media?parent=22956"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.agentsoft.co.kr\/index.php\/wp-json\/wp\/v2\/categories?post=22956"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.agentsoft.co.kr\/index.php\/wp-json\/wp\/v2\/tags?post=22956"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}