""ET WEB_SPECIFIC_APPS LG Simple Editor Malicious JSP Disguised as BMP Upload Attempt (CVE-2023-40498)""

SID: 2049212

Revision: 2

Class Type: attempted-admin

Metadata: attack_target Web_Server, created_at 2023_11_15, cve CVE_2023_40498, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, updated_at 2023_11_16

Reference:

  • cve

  • 2023-40498

Protocol: tcp

Source Network: any

Source Port: any

Destination Network: $HOME_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "POST"

  • Value: "/simpleeditor/imageManager/uploadImage.do"

  • Value: "Content-Disposition|3a 20|form-data|3b 20|name|3d 22|uploadFile|22 3b 20|filename|3d 22|"

  • Value: ".bmp|22 0d 0a|"

  • Value: "Content-Type|3a 20|image/bmp|0d 0a|Content-Transfer-Encoding|3a 20|binary|0d 0a 0d 0a|"

  • Value: "|3c 25 40|page import|3d 22|java.io."

Within: 60

PCRE:

Special Options:

  • http_method

  • fast_pattern

  • http_uri

  • http_client_body

  • http_client_body

  • http_client_body

  • http_client_body

source