CVE-2016-5840
Summary
| CVE | CVE-2016-5840 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-06-30 16:59:00 UTC |
| Updated | 2016-11-28 20:29:00 UTC |
| Description | hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to execute arbitrary code via shell metacharacters in the filename parameter of the Content-Disposition header. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Trend Micro | Deep Discovery Inspector | 3.7 | All | All | All |
| Application | Trend Micro | Deep Discovery Inspector | 3.81 | All | All | All |
| Application | Trend Micro | Deep Discovery Inspector | 3.82 | All | All | All |
| Application | Trend Micro | Deep Discovery Inspector | 3.7 | All | All | All |
| Application | Trend Micro | Deep Discovery Inspector | 3.81 | All | All | All |
| Application | Trend Micro | Deep Discovery Inspector | 3.82 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| JVN#55428526: Deep Discovery Inspector vulnerable to remote code execution | JVN | jvn.jp | |
| Zero Day Initiative | MISC | www.zerodayinitiative.com | |
| JVNDB-2016-000103 - JVN iPedia | JVNDB | jvndb.jvn.jp | |
| Remote Code Execution Vulnerability - Deep Discovery Inspector | CONFIRM | esupport.trendmicro.com | Vendor Advisory |
| Trend Micro Deep Discovery 3.7/3.8 SP1 (3.81)/3.8 SP2 (3.82) - 'hotfix_upload.cgi' Filename Remote Code Execution - Linux webapps Exploit | EXPLOIT-DB | www.exploit-db.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.