Short Name |
HTTP:APACHE:FILTER-DISPATCHER |
|---|---|
Severity |
Medium |
Recommended |
Yes |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
Apache Struts FilterDispatcher and DefaultStaticContentLoader Classes Directory Traversal |
Release Date |
2011/07/26 |
Update Number |
1961 |
Supported Platforms |
di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+ |
This signature detects attempts to exploit a known directory traversal vulnerability in the Apache Struts. It is due to an input validation error in Struts that does not properly sanitize the URI for directory traversal patterns. Successful exploitation allows unauthenticated remote attackers to disclose or access arbitrary files on the vulnerable server. The target will not exhibit any unusual behaviour as a result of this attack. A successful attack will allow the attacker to gain access to restricted files. This may lead to disclosure of sensitive information.