Описание
The hotfix_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the file name of an uploaded file.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 2.6.1062 (включая)
cpe:2.3:a:trendmicro:threat_discovery_appliance:*:r1:*:*:*:*:*:*
EPSS
Процентиль: 66%
0.00526
Низкий
7.3 High
CVSS3
6 Medium
CVSS2
Дефекты
CWE-284
Связанные уязвимости
CVSS3: 7.3
github
больше 3 лет назад
The hotfix_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the file name of an uploaded file.
EPSS
Процентиль: 66%
0.00526
Низкий
7.3 High
CVSS3
6 Medium
CVSS2
Дефекты
CWE-284