SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.
SERVER-WEBAPP cecececeevgrebebe12312 Symantec Messaging Gateway save.do cross site request forgery attempt
123
123
No public information
No known false positives
Cisco Talos Intelligence Group
Rule Categories::Browser::Firefox
Rule Categories::Browser::Chrome
Local File Inclusion
Local File Inclusion (LFI) attackers attempt to trick the web server into executing a file local to its own file system. The attacker might have saved the file there in another way first, or the target file could be a local executable that should not be accessible to the web server otherwise. A successful LFI can lead to data leaks or remote code execution. Avoid dynamic inclusion of user input files, or whitelist files that may be included.
CVE-2012-0308 |
Loading description
|