ESF.pfSense.Snort.SnortLogView.PHP.Information.Disclosure

description-logoDescription

This indicates an attack attempt against an Information Disclosure vulnerability in the pfSense Snort service.
The vulnerability is due to an invalid input error when a vulnerable script handles a crafted HTTP request. A remote attacker can exploit this to gain unauthorized access to sensitive information via a crafted HTTP request.

affected-products-logoAffected Products

Electric Sheep Fencing pfSense Snort 3.0.2

Impact logoImpact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

recomended-action-logoRecommended Actions

Currently we are unaware of any vendor supplied patch for this issue.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2020-11-04 16.956 Name:ESF.
PfSense.
Snort.
SnortLogView.
PHP.
Information.
Disclosure:ESF.
pfSense.
Snort.
SnortLogView.
PHP.
Information.
Disclosure