""ET WEB_SERVER HP OpenView /OvCgi/Toolbar.exe Accept Language Heap Buffer Overflow Attempt""

SID: 2010864

Revision: 9

Class Type: web-application-attack

Metadata: created_at 2010_07_30, cve CVE_2009_0921, confidence High, updated_at 2011_01_20

Reference:

  • cve

  • 2009-0921

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: any

Destination Network: $HTTP_SERVERS

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "POST"

  • Value: "/OvCgi/Toolbar.exe"

  • Value: "Accept-Language|3A|"

  • Value: !"|0A|"

Within: 1350

PCRE:

Special Options:

  • nocase

  • http_method

  • nocase

  • http_uri

  • nocase

source