Back to Rule

Rule History

SID: 2025574 • Source: et/open

Versions (4)

Version DetailsCurrent

Rev: 3May 10, 2018, 12:00 PM

ET WEB_SPECIFIC_APPS Apache ActiveMQ File Upload RCE (CVE-2016-3088)

alert http any any -> $HTTP_SERVERS 8161 (msg:"ET WEB_SPECIFIC_APPS Apache ActiveMQ File Upload RCE (CVE-2016-3088)"; flow:established,to_server; http.method; content:"MOVE"; http.header; content:"Destination|3a 20|"; reference:cve,2016-3088; reference:url,www.exploit-db.com/exploits/42283/; classtype:attempted-admin; sid:2025574; rev:3; metadata:attack_target Web_Server, created_at 2018_05_10, cve CVE_2016_3088, deployment Datacenter, signature_severity Minor, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_08_25;)

May 10, 2018, 12:00 PM

Aug 25, 2020, 12:00 PM

Sep 21, 2024, 3:00 AM

Sep 29, 2025, 9:34 PM

rules/emerging-web_specific_apps.rules