HTTP: Opensis Modname Parameter Remote PHP Code Injection

This signature detects attempts to exploit a known vulnerability against Opensis. A successful exploit can lead to remote php code injection.

Extended Description

Eval injection vulnerability in ajax.php in openSIS 4.5 through 5.2 allows remote attackers to execute arbitrary PHP code via the modname parameter.

Affected Products

Os4ed opensis

References

CVE: CVE-2013-1349

Short Name
HTTP:MISC:OPENSIS-PARAM-PHP-INJ
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2013-1349 Code Injection Modname Opensis PHP Parameter Remote
Release Date
06/09/2015
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Os4ed

CVSS Score

7.5

Found a potential security threat?