""ET WEB_SERVER Webmin RCE CVE-2019-15107""

SID: 2027896

Revision: 2

Class Type: attempted-admin

Metadata: affected_product Web_Server_Applications, attack_target Web_Server, created_at 2019_08_18, cve CVE_2019_15107, deployment Perimeter, deployment Internal, deployment Datacenter, signature_severity Critical, updated_at 2019_08_18

Reference:

  • cve

  • 2019-15107

Protocol: tcp

Source Network: any

Source Port: any

Destination Network: any

Destination Port: [$HTTP_PORTS,10000]

Flow: to_server,established

Contents:

  • Value: "POST"

  • Value: "/password_change.cgi" Depth: 20

  • Value: "|7c|"

Within:

PCRE:

Special Options:

  • http_method

  • fast_pattern

  • http_client_body

source