APP: BigAnt Server File Upload

This signature detects attempts to exploit a known vulnerability against BigAnt Server. Successful exploitation would result in arbitrary code execution with the privileges of the System user.

Extended Description

BigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to create arbitrary files under AntServer\DocData\Public via unspecified vectors.

Affected Products

Bigantsoft bigant_im_message_server

References

BugTraq: 57214

CVE: CVE-2012-6274

Short Name
APP:BIGANT-SERVER-FILE-UPLOAD
Severity
Major
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
BigAnt CVE-2012-6274 File Server Upload bid:57214
Release Date
04/08/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
Port
tcp/6661
False Positive
Unknown
Vendors

Bigantsoft

CVSS Score

5.0

Found a potential security threat?