Short Name |
HTTP:COBALT:SEC-REQ-PROBE |
---|---|
Severity |
Minor |
Recommended |
No |
Category |
HTTP |
Keywords |
Cobalt RaQ 4 Security Hardening Update Discovery Request |
Release Date |
2003/04/22 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to identify Cobalt RaQ 4 servers with the Security Hardening Update installed. The Secure Hardening Update contains vulnerabilities that attackers can exploit to execute arbitrary commands.
The RaQ4 is a server appliance distributed and maintained by Sun Microsystems. A vulnerability has been reported in the web administration interface of the RaQ4. It is possible for a remote attacker to execute commands. By passing malicious email parameter to the vulnerable CGI script, commands are carried out in the security context of the administration server. This vulnerability only affects RaQ4 servers with the RaQ4 Security Hardening Package (SHP) installed. The SHP is not installed by default.