File: 2321.txt

package info (click to toggle)
snort 2.7.0-20.4
  • links: PTS
  • area: main
  • in suites: lenny
  • size: 34,512 kB
  • ctags: 18,772
  • sloc: ansic: 115,404; sh: 10,893; makefile: 1,372; perl: 487; sql: 213
file content (58 lines) | stat: -rw-r--r-- 1,078 bytes parent folder | download | duplicates (6)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
Rule:

--
Sid:
2321

--
Summary:
This event is generated when an attempt is made to access foxweb.exe, a 
CGI web application running on a server.

--
Impact:
Possible execution of arbitrary code of the attackers choosing.

--
Detailed Information:
The FoxWeb application is used to communicate with FoxPro databases. The
program foxweb.exe contains an error that may allow an attacker to
execute arbitrary code of their choosing and possibly gain unauthorized
administrator access to the server.

--
Affected Systems:
	FoxWeb 2.5 and prior

--
Attack Scenarios:
An attacker can exploit weaknesses to gain access as the administrator by supplying input of
their choosing to the CGI program.

--
Ease of Attack:
Simple.

--
False Positives:
None known.

--
False Negatives:
None known.

--
Corrective Action:
Ensure the system is using an up to date version of the software and has
had all vendor supplied patches applied.

--
Contributors:
Sourcefire Research Team
Brian Caswell <bmc@sourcefire.com>
Nigel Houghton <nigel.houghton@sourcefire.com>

--
Additional References:

--