Security Portal

Intrusion Prevention Service

 
Signature Version: 4.788

 



WEB Apache Continuum Arbitrary Command Execution -1
 
Threat Level: High
Release Date: 2016/6/17
 
Category: Access Control
Signature ID: 1132674
Included In: Full
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix
 
Description: A command injection was found in Apache Continuum <= 1.4.2. By injecting a command into the installation.varValue POST parameter to /continuum/saveInstallation.action, a shell can be spawned.
 
Impact: Remote code execution
Recommendation: Update vendor's patch.
 
False Positive: None
False Negative: None
 
Additional Information (Links open in new window):
N/A
Reference(s): EDB-39886; CVE-2006-unknown; msf
 

Search the Threat Database
Enter Rule ID or Name