Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:PHP:IBM-PROVENTIA-RFI

Severity

High

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

IBM Proventia Sensor Appliance Remote File Inclusion

Release Date

2013/06/18

Update Number

2273

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: IBM Proventia Sensor Appliance Remote File Inclusion


This signature detects attempts to exploit a known vulnerability in the IBM Proventia Sensor Appliance. A successful attack can lead to arbitrary code execution.

Extended Description

The IBM Proventia Sensor Appliance is prone to multiple input-validation vulnerabilities, including multiple remote file-include issues and a cross-site scripting issue. An attacker can exploit these issues to steal cookie-based authentication credentials, view files, and to execute arbitrary server-side script code on an affected device in the context of the webserver process. Other attacks are also possible. IBM Proventia Sensor Appliance CX5108 and GX5008 are vulnerable.

Affected Products

  • IBM Proventia Sensor Appliance GX5008
  • IBM Proventia Sensor Appliance GX5108

References

  • BugTraq: 24864
  • CVE: CVE-2007-3831

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out