The hotfix_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the file name of an uploaded file.
References
| Link | Resource |
|---|---|
| http://packetstormsecurity.com/files/142220/Trend-Micro-Threat-Discovery-Appliance-2.6.1062r1-hotfix_upload.cgi-Remote-Code-Execution.html | Exploit Third Party Advisory VDB Entry |
| http://packetstormsecurity.com/files/142220/Trend-Micro-Threat-Discovery-Appliance-2.6.1062r1-hotfix_upload.cgi-Remote-Code-Execution.html | Exploit Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2017-04-28 19:59
Updated : 2025-04-20 01:37
NVD link : CVE-2016-8588
Mitre link : CVE-2016-8588
CVE.ORG link : CVE-2016-8588
JSON object : View
Products Affected
trendmicro
- threat_discovery_appliance
CWE
CWE-284
Improper Access Control
