iSID Analyst Knowledge Base

Definitions, and additional context on iSID alerts along with helpful recommendations

SERVER-WEBAPP Cisco Security Manager XmpFileDownloadServlet directory traversal attempt

This Snort rule is specifically crafted to detect attempts to exploit the directory traversal vulnerability in the Cisco Security Manager's XmpFileDownloadServlet. If the specified patterns are detected in the HTTP URI and body, the rule triggers an alert.

SERVER-WEBAPP Cisco Security Manager XmpFileDownloadServlet directory traversal attempt

this Snort rule is specifically crafted to detect attempts to exploit the directory traversal vulnerability in Cisco Security Manager's XmpFileDownloadServlet. If the specified patterns are detected in the HTTP URI and body, the rule triggers an alert.

SERVER-APACHE Apache Struts wildcard matching OGNL remote code execution attempt

This Snort rule is specifically crafted to detect attempts to exploit specific patterns associated with Apache Struts vulnerabilities related to wildcard matching and OGNL remote code execution in the HTTP URI of an established TCP connection on standard HTTP ports. If the patterns are detected, the rule triggers an alert.

SERVER-APACHE Apache Struts wildcard matching OGNL remote code execution attempt

This Snort rule is specifically crafted to detect attempts to exploit specific patterns associated with Apache Struts vulnerabilities related to wildcard matching and OGNL remote code execution in the HTTP URI of an established TCP connection on standard HTTP ports.

SERVER-APACHE Apache Struts wildcard matching OGNL remote code execution attempt

This Snort rule is specifically crafted to detect attempts to exploit specific patterns associated with Apache Struts vulnerabilities related to wildcard matching and OGNL remote code execution in the HTTP URI of an established TCP connection on standard HTTP ports. If the patterns are detected, the rule triggers an alert.