SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.
SERVER-WEBAPP Netgear ProSafe NMS arbitrary JSP file upload attempt
This rule looks for HTTP requests targeting the file upload endpoint and containing JSP code markers in the request body. Successful exploitation could allow an attacker to place and execute malicious server‑side scripts on the affected device.
This rule fires on attempts to upload arbitrary JSP files to Netgear ProSafe NMS web management interfaces.
No public information
No known false positives
Cisco Talos Intelligence Group
MITRE::ATT&CK Framework::Enterprise::Privilege Escalation::Exploitation for Privilege Escalation
MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application
Vulnerability::Severity::Critical
Vulnerability::Severity::High
Rule Categories::Server::Web Applications
N/A
Not Applicable
CVE-2016-1525 |
Loading description
|
CVE-2024-5247 |
Loading description
|