Trend Micro OfficeScan 'Proxy.php' Command Injection Vulnerability
BID:100130
Info
Trend Micro OfficeScan 'Proxy.php' Command Injection Vulnerability
| Bugtraq ID: | 100130 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-11394 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2017 12:00AM |
| Updated: | Aug 02 2017 12:00AM |
| Credit: | Steven Seeley from Source Incite. |
| Vulnerable: |
Trend Micro OfficeScan XG (12.0) Trend Micro OfficeScan 11.0 SP1 |
| Not Vulnerable: |
Trend Micro OfficeScan XG CP 1641 r1 Trend Micro OfficeScan 11.0 SP1 CP 6392 r1 |
Discussion
Trend Micro OfficeScan 'Proxy.php' Command Injection Vulnerability
Trend Micro OfficeScan is prone to a command-injection vulnerability because it fails to properly sanitize user-supplied input.
Successfully exploiting this issue may allow an attacker to execute arbitrary code in the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Trend Micro OfficeScan is prone to a command-injection vulnerability because it fails to properly sanitize user-supplied input.
Successfully exploiting this issue may allow an attacker to execute arbitrary code in the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Trend Micro OfficeScan 'Proxy.php' Command Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].