EXPL_JSP_CommVault_CVE_2025_57791_Aug25_1
Description
Detects potential exploit for WT-2025-0049, Post-Auth RCE with QCommand Path Traversal
Query · yara
strings:
$s1 = "<App_GetUserPropertiesResponse>" ascii
$s2 = "getMethod('getRuntime').invoke(null).exec(param.cmd)" ascii
condition:
filesize < 50KB and all of them