HTTP: SysAid Help Desk Authenticated Remote Code Execution

This signature detects attempts to exploit a known vulnerability against SysAid Help Desk. A successful attack can lead to arbitrary code execution.

Extended Description

Unrestricted file upload vulnerability in ChangePhoto.jsp in SysAid Help Desk before 15.2 allows remote administrators to execute arbitrary code by uploading a file with a .jsp extension, then accessing it via a direct request to the file in icons/user_photo/.

Affected Products

Sysaid sysaid

Short Name
HTTP:CTS:SYSAID-HELP-DESK-RCE
Severity
Major
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
Authenticated CVE-2015-2994 Code Desk Execution Help Remote SysAid
Release Date
09/23/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Occasionally
Vendors

Sysaid

CVSS Score

6.5

Found a potential security threat?