HTTP: Xplico Unauthenticated Command Injection

This signature detects attempts to exploit a known vulnerability against Xplico. A successful attack can lead to Command Injection.

Extended Description

Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name of an uploaded PCAP file. NOTE: this issue can be exploited without authentication by leveraging the user registration feature.

Affected Products

Xplico xplico

Short Name
HTTP:CTS:XPLICO-UNAUTH-CMD-INJ
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2017-16666 Command Injection Unauthenticated Xplico
Release Date
09/10/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Xplico

CVSS Score

9.0

Found a potential security threat?