*** NK8 RELS 3307 Release *** Total number of signatures: 3185 Description ================================================================== In this signature, we addressed the exploits/vulnerabilities and applications as below: Added 19 rule(s): --------------- 1133311 WEB Teampass upload.files.php Arbitrary File Upload 1133319 WEB SugarCRM rest_data PHP Object Deserialization 1133322 WEB op5 Monitor command_test.php Command Injection -1 1133325 SSL OpenSSL SSL3_AL_WARNING Denial of Service (CVE-2016-8610) 1133327 WEB Joomla! CMS Policy Bypass and Privilege Escalation Vulnerabilities -2 (CVE-2016-8869) 1133331 WEB Alienvault Unified Security Management and OSSIM gauge.php SQL Injection -3 (CVE-2016-8582) 1133332 WEB Microsoft SQL RDBMS Engine UNC Path Injection Privilege Escalation -2 (CVE-2016-7250) 1133333 WEB Trend Micro Virtual Mobile Infrastructure apns_worker.py Command Injection -1 (CVE-2016-6270) 1133334 WEB Trend Micro Virtual Mobile Infrastructure apns_worker.py Command Injection -2 (CVE-2016-6270) 1133337 WEB Trend Micro Smart Protection Server admin_notification.php Command Injection -1 (CVE-2016-6267) 1133343 WEB Wavelink Emulation License Server HTTP Header Processing Buffer Overflow -3 (CVE-2015-4059) 1133351 EXPLOIT Netop Remote Control dws File Stack Buffer Overflow -3 1133353 VIRUS Eicar test string -2 1133369 VIRUS Eicar test string -3 1160051 PRIPROTOCOL Thunder transfer via UDP -2 1160053 IM AliWW login via TCP -4 1160054 IM AliWW transfer via TCP -4 1160055 IM AliWW transfer via TCP -5 1160063 MEDIA iQIYI/PPS media via TCP -19 Modified 15 rule(s): --------------- 1050694 WEB SQL injection attempt -41 1051723 VIRUS Eicar test string 1055106 WEB PHP Arbitrary Code Injection -1.a 1055189 WEB SQL injection attempt -10 1056091 WEB PHP Arbitrary Code Injection -3.a 1056205 WEB PHP Arbitrary Code Injection -4.a 1059902 EXPLOIT Netcore Router Backdoor Access 1069325 CA Yahoo Authentication via SSL -7 1131343 WEB Generic Remote Javascript Upload and Execution -1.a 1131572 WEB Symantec Endpoint Protection ConsoleServlet ResetPassword Policy Bypass -1.u (CVE-2015-1486) 1131754 WEB SQL injection attempt -73.a 1131889 EXPLOIT Apple SceneKit qlmanage deaElement setElement Buffer Overflow (CVE-2015-3783) 1132120 WEB Generic Remote Javascript Upload and Execution -2.a 1132121 WEB Generic Remote Javascript Upload and Execution -3.a 1133162 WEB Joomla! CMS Policy Bypass and Privilege Escalation Vulnerabilities -1 (CVE-2016-8869) Deleted 0 rule(s): ---------------