Short Name |
APP:SYMC:IM-MGR-WEB-UI-INJ |
---|---|
Severity |
High |
Recommended |
Yes |
Recommended Action |
Drop |
Category |
APP |
Keywords |
Symantec IM Manager Web Interface ProcessAction Code Execution |
Release Date |
2013/05/29 |
Update Number |
2268 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vsrx-12.1+ |
This signature detects a known vulnerability against Symantec IM Manager Web Interface. It is due to improper input validation on the rdProcess variable in rdprocess.aspx. A remote attacker can exploit this vulnerability by sending specially crafted request to the web Interface. Successful exploitation will result in execution of arbitrary code in the context of the web server.
Symantec IM Manager is prone to a vulnerability that will let attackers run arbitrary code. Remote attackers can exploit this issue to run arbitrary code in the context of the affected application. IM Manager versions prior to 8.4.18 are affected.