*** NK8 RELS 3492 Release *** Total number of signatures: 3073 Description ================================================================== In this signature, we addressed the exploits/vulnerabilities and applications as below: Added 13 rule(s): --------------- 1137235 WEB LinuxKI Toolset 6.01 Remote Command Execution -1.1 (CVE-2020-7209) 1137236 WEB LinuxKI Toolset 6.01 Remote Command Execution -1.2 (CVE-2020-7209) 1137293 WEB SAP NetWeaver Application Server JAVA Disclosed (RECON) -1.1 (CVE-2020-6287) 1137296 WEB SAP NetWeaver Application Server JAVA Disclosed (RECON) -1.2 (CVE-2020-6287) 1137304 WEB Zivif Camera iptest.cgi Blind Remote Command Execution (CVE-2017-171069) 1137317 FILE Microsoft Windows CAB File Parsing Directory Traversal (CVE-2020-1300) 1137318 WEB NetGear DGN1000B Wireless Router Multiple Security Vulnerabilities (BID-57836) 1137319 DNS Microsoft Windows DNS Server Remote Code Execution Vulnerability -1.2 (CVE-2020-1350) 1137320 WEB Cayin xPost wayfinder_seqid SQLi to RCE (CVE-2020-7356) 1137321 WEB Realtek SDK Miniigd UPnP SOAP Command Execution -1.2 (CVE-2014-8361) 1137326 WEB Eir D1000 Wireless Router WAN Side Remote Command Injection -1.1 (CVE-2016-10372) 1137327 WEB Eir D1000 Wireless Router WAN Side Remote Command Injection -1.2 (CVE-2016-10372) 1137328 WEB D-Link Multiple Routers HNAP Protocol Security Bypass Vulnerability -1.2 (BID-37690) Modified 4 rule(s): --------------- 1068665 MEDIA YouTube access via UDP -3 1134286 WEB Realtek SDK Miniigd UPnP SOAP Command Execution -1.1 (CVE-2014-8361) 1134287 WEB Huawei Home Gateway SOAP Command Execution (CVE-2017-17215) 1137255 DNS Microsoft Windows DNS Server Remote Code Execution Vulnerability -1.1 (CVE-2020-1350) Deleted 45 rule(s): --------------- 1132438 WEB Directory Traversal -27.x (old rule) 1132446 WEB Directory Traversal -5.e (old rule) 1132898 WEB-CLIENT Suspicious HTML Iframe Tag -15 (Ransomware Attack Vector) (old rule) 1132990 ICS GE MDS PulseNET FileDownloadServlet Directory Traversal (CVE-2015-6459) (old rule) 1132994 WEB-CLIENT Javascript Obfuscation in Exploit Kits - 80 (Ransomware Attack Vector) (old rule) 1132995 SIP IBM WebSphere Application Server SIP Processing Denial of Service (CVE-2016-2960) (old rule) 1132996 EXPLOIT Microsoft Windows Authentication Kerberos NTLM Fallback Security Bypass (CVE-2016-3237) (old rule) 1133004 FILE Microsoft Windows Els.dll Insecure Library Loading -1 (CVE-2015-6128) (old rule) 1133012 FILE Microsoft Office Memory Corruption Vulnerability (CVE-2016-3381) (old rule) 1133016 WEB-CLIENT Microsoft Scripting Engine Memory Corruption Vulnerability (CVE-2016-3377) (old rule) 1133021 FILE Microsoft Office Memory Corruption Vulnerability (CVE-2016-3360) (old rule) 1133023 FILE Microsoft Office Memory Corruption Vulnerability (CVE-2016-3358) (old rule) 1133037 DB Oracle MySQL Remote Root Code Execution Vulnerability -1 (CVE-2016-6662) (old rule) 1133038 DB Oracle MySQL Remote Root Code Execution Vulnerability -2 (CVE-2016-6662) (old rule) 1133047 FILE Microsoft Windows PDF Library CVE-2016-3319 Memory Corruption (old rule) 1133060 WEB-CLIENT Javascript Obfuscation in Exploit Kits - 82 (Ransomware Attack Vector) (old rule) 1133061 FILE Microsoft Office CVE-2016-3318 Remote Code Execution -1 (old rule) 1133064 WEB Trend Micro Control Manager AdHocQuery_Processor.aspx SQL Injection -1 (old rule) 1133068 WEB-CLIENT Javascript Obfuscation in Exploit Kits - 83 (Ransomware Attack Vector) (old rule) 1133072 WEB SearchBlox Stored Cross-Site Scripting (CVE-2015-0967) (old rule) 1133073 WEB-CLIENT Internet Explorer Memory Corruption Vulnerability -1 (CVE-2016-3383) (old rule) 1133147 WEB Apache Jetspeed PageManagementService Cross-Site Scripting (CVE-2016-0711) (old rule) 1133183 WEB Joomla! Remote Account Creation Vulnerability -1 (CVE-2016-8870) (old rule) 1133191 WEB Drupal RESTful Web Services Module Default Page Callback Function Remote php Command Execution (EDB-40130) (old rule) 1133192 TELNET Cisco Adaptive Security Appliance Telnet CLI Privilege Escalation (CVE-2016-6367) (old rule) 1133267 WEB-CLIENT Torbrowser Javascript Exploit (old rule) 1133268 WEB SQL injection attempt -84 (old rule) 1133269 SMB Microsoft Windows LSASS Authenticate Message Denial of Service -1 (CVE-2016-7237) (old rule) 1133275 WEB Nagios Network Analyzer Report Generator Command Injection -1 (old rule) 1133284 WEB-CLIENT Generic Javascript Obfuscation -32 (old rule) 1133296 WEB-CLIENT Microsoft Edge TypedArray.sort Use After Free -1 (CVE-2016-7288) (old rule) 1133297 WEB-CLIENT Microsoft Browser Information Disclosure Vulnerability (CVE-2016-7227) (old rule) 1133298 WEB-CLIENT Microsoft Edge Scripting Engine Memory Corruption Vulnerability -1 (CVE-2016-7287) (old rule) 1133300 WEB-CLIENT Microsoft Edge CVE-2016-7286 Memory Corruption (old rule) 1133301 WEB-CLIENT Microsoft Edge Memory Corruption Vulnerability (CVE-2016-7279) (old rule) 1133310 WEB Netgear R7000 Command Injection -1.1 (CVE-2016-6277) (old rule) 1133311 WEB Teampass upload.files.php Arbitrary File Upload (old rule) 1133319 WEB SugarCRM rest_data PHP Object Deserialization (old rule) 1133322 WEB op5 Monitor command_test.php Command Injection -1 (old rule) 1133327 WEB Joomla! CMS Policy Bypass and Privilege Escalation Vulnerabilities -2 (CVE-2016-8869) (old rule) 1133331 WEB Alienvault Unified Security Management and OSSIM gauge.php SQL Injection -3 (CVE-2016-8582) (old rule) 1133334 WEB Trend Micro Virtual Mobile Infrastructure apns_worker.py Command Injection -2 (CVE-2016-6270) (old rule) 1133337 WEB Trend Micro Smart Protection Server admin_notification.php Command Injection -1 (CVE-2016-6267) (old rule) 1133343 WEB Wavelink Emulation License Server HTTP Header Processing Buffer Overflow -3 (CVE-2015-4059) (old rule) 1133351 EXPLOIT Netop Remote Control dws File Stack Buffer Overflow -3 (old rule)