HTTP: nopCommerce BackupAction Directory Traversal

This signature detects attempts to exploit a known vulnerability against nopCommerce BackupAction. A successful attack can lead to directory traversal and denial of service.

Extended Description

nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature.

Affected Products

Nopcommerce nopcommerce

References

CVE: CVE-2022-28451

Short Name
HTTP:DIR:NOP-COMMERCE-DIR-TRAV
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
BackupAction CVE-2022-28451 Directory Traversal nopCommerce
Release Date
05/16/2022
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3492
False Positive
Unknown
Vendors

Nopcommerce

Found a potential security threat?