HTTP: Open Web Analytics Privilege Escalation

This signature detects attempts to exploit a known vulnerability against Open Web Analytics. A successful attack can lead to elevation of privilege and arbitrary code execution.

Extended Description

Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes. This occurs because files generated with '<?php (instead of the intended "<?php sequence) aren't handled by the PHP interpreter.

Affected Products

Openwebanalytics open_web_analytics

Short Name
HTTP:CTS:OPEN-WEB-PRIV-ESC
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Analytics CVE-2022-24637 Escalation Open Privilege Web
Release Date
07/07/2023
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3614
False Positive
Unknown
Vendors

Openwebanalytics

Found a potential security threat?