SERVER-OTHER -- Snort has detected traffic exploiting vulnerabilities in a server in the network.
SERVER-OTHER Progress WhatsUp Gold WriteDataFile directory traversal attempt
This rule looks for a .NET Message Framing Protocol sized envelope record that includes the "WriteDataFile" operation together with a parent directory traversal pattern in the request payload. Successful exploitation allows an attacker to write arbitrary files to arbitrary locations on the target system, potentially achieving remote code execution.
This rule fires on attempts to exploit a directory traversal vulnerability in Progress WhatsUp Gold servers.
Public information/Proof of Concept available
No known false positives
Cisco Talos Intelligence Group
Rule Categories::Server::Other
MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application
Vulnerability::Severity::High
Vulnerability::Severity::Critical
Directory Traversal
A Directory Traversal attack targets HTTP traffic and allows the attacker to access directories outside the applications own, potentially exposing sensitive system files to leakage or overwriting. This is also known as Directory Climbing, Path Traversal, or Backtracking. An alert on this kind of attack indicates a vulnerability in security validation of user input that allows a "traverse to parent directory" or "../" command to pass through. Protect your site by filtering all user input, removing any characters but the allowed data.
CVE-2024-4883 |
Loading description
|