Short Name |
SCAN:MISC:HTTP:POST-QUERY-PROBE |
---|---|
Severity |
Info |
Recommended |
No |
Category |
SCAN |
Keywords |
Post Query Probe |
Release Date |
2003/04/22 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects access to the post-query CGI script, a common target of vulnerability scans.
NCSA Post-query is prone to a remotely exploitable buffer overflow condition. This is due to insufficient bounds checking when handling HTTP POST requests. It is possible for remote attackers to corrupt sensitive regions of memory with attacker-supplied values, possibly resulting in execution of arbitrary code.