Rule Category

SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.

Alert Message

SERVER-WEBAPP PHP FPM env_path_info buffer underflow attempt

Rule Explanation

This event is generated when Snort detects an attempt to add or modify PHP configuration via the URL. Impact: Web Application Attack Details: Systems that are configured to run PHP in a potentially unsafe manner could allow an attacker to modify PHP runtime configuration via the URL. An example of this can be found in the proof-of-concept for CVE-2019-11043. Ease of Attack: Simple

What To Look For

No information provided

Known Usage

No public information

False Positives

No known false positives


Rule Groups

No rule groups


Additional Links

Rule Vulnerability

CVE Additional Information

