Short Name |
HTTP:MISC:CVSTRAC-FILEDIFF-RCE |
---|---|
Severity |
Major |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
CVSTrac filediff Remote Command Execution |
Release Date |
2013/05/08 |
Update Number |
2261 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to exploit a known vulnerability against CVSTrac web-based bug and patch-set tracking system for CVS. A successful attack can lead to arbitrary code execution.
CVSTrac is affected by a remote command execution vulnerability in the 'filediff' functionality. This issue is due to an input validation error that allows for the appending of shell commands. An attacker could leverage this issue to execute arbitrary shell commands on a vulnerable computer with the privileges of the web server process.