HTTP: Progress WhatsUp Gold GetFileWithoutZip Directory Traversal
This signature detects attempts to exploit a known vulnerability against Progress. A successful attack can lead to directory traversal and arbitrary code execution.
Extended Description
In WhatsUp Gold versions released before 2023.1.3,an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\nmconsole privileges.
Affected Products
Progress whatsup_gold
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Progress