Short Name |
HTTP:DIR:PARAM-TRAVERSE |
|---|---|
Severity |
Medium |
Recommended |
Yes |
Category |
HTTP |
Keywords |
directory traversal |
Release Date |
2003/08/12 |
Update Number |
1213 |
Supported Platforms |
di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+ |
This signature detects directory traversal attempts within HTTP GET or POST form parameters. Attackers can exploit a poorly-written CGI program to access or modify private files.
Successful exploitation of this vulnerability would allow remote intruders unauthorized access to files that are outside of the Web root directory. Hackers may be able to view or write files with the privilege of the Web server.