SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.
SERVER-WEBAPP Microsoft SharePoint Server remote code execution attempt
This rule looks for attempts to abuse workflow pipelines within Microsoft SharePoint Server. Attackers who abuse this exploit could execute code remotely on the host.
This rule looks for attempts to exploit CVE-2025-49701.
No public information
No known false positives
Cisco Talos Intelligence Group
No rule groups
Command Injection
Command Injection attacks target applications that allow unsafe user-supplied input. Attackers transmit this input via forms, cookies, HTTP headers, etc. and exploit the applications permissions to execute system commands without injecting code.
CVE-2025-49701 |
Loading description
|