HTTP: Alcatel-Lucent OmniPCX Enterprise FastJSData Arbitrary Command Execution

This signature detects attempts to exploit a known vulnerability against Alcatel-Lucent OmniPCX Enterprise. A successful attack can lead to arbitrary command execution.

Extended Description

OmniPCX Office with Internet Access services is prone to a vulnerability that lets remote attackers execute arbitrary commands because it fails to sanitize user-supplied input. Attackers can exploit this issue to execute arbitrary commands and potentially compromise the affected server. The issue affects versions since OmniPCX Office 210/061.1. NOTE: This BID was previously titled 'OmniPCX Office Unspecified Information Disclosure Vulnerability', but has been changed to better reflect the issue.

Affected Products

Alcatel-lucent omnipcx_office

References

BugTraq: 28758

CVE: CVE-2008-1331

Short Name
HTTP:MISC:ALCATEL-OMNIPCX-RCE
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Alcatel-Lucent Arbitrary CVE-2008-1331 Command Enterprise Execution FastJSData OmniPCX bid:28758
Release Date
04/24/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Alcatel-lucent

CVSS Score

10.0

Found a potential security threat?