CVE-2017-9032
Summary
| CVE | CVE-2017-9032 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-05-26 01:29:00 UTC |
| Updated | 2021-09-09 17:33:00 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allow remote attackers to inject arbitrary web script or HTML via the (1) T1 or (2) tmLastConfigFileModifiedDate parameter to log_management.cgi. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Trendmicro | Serverprotect | 3.0 | All | All | All |
| Application | Trendmicro | Serverprotect | 3.0 | All | All | All |
| Application | Trendmicro | Serverprotect | 3.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Trend Micro ServerProtect Disclosure / CSRF / XSS ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| Full Disclosure: [CORE-2017-0002] - Trend Micro ServerProtect Multiple Vulnerabilities | FULLDISC | seclists.org | Exploit, Mailing List, Third Party Advisory |
| Multiple Vulnerabilities - ServerProtect for Linux 3.0 | CONFIRM | success.trendmicro.com | Patch, Vendor Advisory |
| Trend Micro ServerProtect for Linux Multiple Bugs Let Remote Users Execute Arbitrary Code and Conduct Cross-Site Scripting and Cross-Site Request Forgery Attacks and Let Local Users Gain Elevated Privileges - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Trend Micro ServerProtect Multiple Vulnerabilities | Core Security | MISC | www.coresecurity.com | Exploit, Technical Description, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.