APP: NUUO CMS Sourceserver SQL Injection

This signature detects attempts to exploit a known vulnerability against NUUO CMS. A successful attack can lead to command injection and arbitrary code execution.

Extended Description

NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can be used to inject SQL into an executing statement and allow arbitrary code execution.

Affected Products

Nuuo nuuo_cms

Short Name
APP:MISC:NUUO-CMS-SQL-INJ
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
CMS CVE-2018-18982 Injection NUUO SQL Sourceserver
Release Date
06/02/2020
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
Port
TCP/5180
False Positive
Unknown
Vendors

Nuuo

CVSS Score

6.5

Found a potential security threat?