Short Name |
HTTP:PHP:PMACHINE-PATH-DISC |
---|---|
Severity |
Warning |
Recommended |
No |
Category |
HTTP |
Keywords |
pMachine Path Disclosure |
Release Date |
2003/07/09 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to exploit a known vulnerability in pMachine, an online publishing application. pMachine version 2.2.1 and other versions are vulnerable. Attackers can send a malicious HTTP request to the pMachine Web server to cause some pMachine scripts to return the full path of the pMachine installation. Attackers can use this information in planning future, more targeted attacks.
It has been reported that pMachine is prone to remote a patch disclosure vulnerability when accessing various scripts. When a request is made for a target PHP script, possibly requiring a blank URI parameter, pMachine is said to throw an exception. When this occurs, the resulting error page discloses the installation directory of the respective PHP script.