HTTP: WebSVN Command Injection

This signature detects attempts to exploit a known vulnerability against WebSVN. A successful attack can lead to command injection and arbitrary code execution.

Extended Description

WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.

Affected Products

Websvn websvn

Short Name
HTTP:CTS:WEBSVN-CMD-INJ
Severity
Critical
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
CVE-2021-32305 Command Injection WebSVN
Release Date
08/18/2021
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3411
False Positive
Unknown
Vendors

Websvn

CVSS Score

10.0

Found a potential security threat?