SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.
SERVER-WEBAPP TerraMaster TOS PHP object injection attempt
This rule looks for PHP object injection patterns present in the following parameters in HTTP requests sent to the /module/api.php?mobile/createRaid endpoint on TerraMaster TOS web applications: raidtype, diskstring.
This rule looks for attempts to exploit a PHP object injection vulnerability in TerraMaster TOS web applications.
Attacks/Scans seen in the wild
No known false positives
Cisco Talos Intelligence Group
Rule Categories::Server::Web Applications
MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application
N/A
Not Applicable
CVE-2022-24989 |
Loading description
|