Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:PHP:FAMILY-CONN-CMS-RCE

Severity

Major

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Family Connections CMS less.php Remote Command Execution

Release Date

2012/08/29

Update Number

2179

Supported Platforms

di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: Family Connections CMS less.php Remote Command Execution


This signature detects attempts to exploit a known vulnerability against Family Connections. A successful attack can lead to arbitrary command execution.

Extended Description

dev/less.php in Family Connections CMS (FCMS) 2.5.0 - 2.7.1, when register_globals is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the argv[1] parameter.

Affected Products

  • Haudenschilt family_connections_cms 2.5.0
  • Haudenschilt family_connections_cms 2.5.1
  • Haudenschilt family_connections_cms 2.5.2
  • Haudenschilt family_connections_cms 2.5.3
  • Haudenschilt family_connections_cms 2.5.4
  • Haudenschilt family_connections_cms 2.6.0
  • Haudenschilt family_connections_cms 2.7.0
  • Haudenschilt family_connections_cms 2.7.1

References

  • CVE: CVE-2011-5130
  • URL: https://www.familycms.com/blog/2011/11/security-vulnerability-fcms-2-5-2-7-1/
  • URL: http://sourceforge.net/apps/trac/fam-connections/ticket/407
  • URL: http://rwx.biz.nf/advisories/fc_cms_rce_adv.html

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out