HTTP: SmartSearch.cgi Keywords Input Validation Error

This signature detects attempts to exploit an input validation vulnerability in the keywords parameter in SmartSearch CGI. Attackers can submit a malicious request containing the pipe (|) character to smartsearch.cgi to execute arbitrary commands.

Extended Description

Successful exploitation of the vulnerability could allow an attacker to run arbitrary commands or code with the privileges of the web server.

Short Name
HTTP:CGI:SMARTSEARCH-EXEC
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
Error Input Keywords SmartSearch.cgi Validation
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?