Trend Micro Scanning Engine Report Generation HTML Injection Vulnerability
BID:10456
Info
Trend Micro Scanning Engine Report Generation HTML Injection Vulnerability
| Bugtraq ID: | 10456 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 03 2004 12:00AM |
| Updated: | Jun 03 2004 12:00AM |
| Credit: | Disclosure of this issue is credited to "[email protected]" <[email protected]>. |
| Vulnerable: |
Trend Micro Viruswall 3.0.1 Trend Micro Virusbuster 2001 8.0.2 Trend Micro Virusbuster 2001 8.0.1 Trend Micro Virus Buster Corporate Edition 3.54 Trend Micro Virus Buster Corporate Edition 3.53 Trend Micro Virus Buster Corporate Edition 3.52 Trend Micro Scanning Engine 7.1 Trend Micro ScanMail for Microsoft Exchange 6.1 Trend Micro ScanMail for Microsoft Exchange 3.81 Trend Micro ScanMail for Microsoft Exchange 3.8 Trend Micro ScanMail 1.0 Trend Micro PC-cillin 6.0 Trend Micro PC-cillin 2003 Trend Micro PC-cillin 2002 Trend Micro PC-cillin 2000 Trend Micro OfficeScan For Microsoft SBS 4.5 Trend Micro OfficeScan Corporate Edition for Windows NT Server 3.13 Trend Micro OfficeScan Corporate Edition for Windows NT Server 3.11 Trend Micro OfficeScan Corporate Edition for Windows NT Server 3.5 Trend Micro OfficeScan Corporate Edition for Windows NT Server 3.1.1 Trend Micro OfficeScan Corporate Edition for Windows NT Server 3.0 Trend Micro OfficeScan Corporate Edition 5.58 Trend Micro OfficeScan Corporate Edition 5.0 2 Trend Micro OfficeScan Corporate Edition 3.54 Trend Micro OfficeScan Corporate Edition 3.13 Trend Micro OfficeScan Corporate Edition 3.11 Trend Micro OfficeScan Corporate Edition 3.5 Trend Micro OfficeScan Corporate Edition 3.0 Trend Micro InterScan WebManager 2.1 Trend Micro InterScan WebManager 2.0 Trend Micro InterScan WebManager 1.2 Trend Micro InterScan WebManager 1.2 Trend Micro InterScan VirusWall for Windows NT 5.1 Trend Micro InterScan VirusWall for Windows NT 3.52 build 1466 Trend Micro InterScan VirusWall for Windows NT 3.52 Trend Micro InterScan VirusWall for Windows NT 3.51 Trend Micro InterScan VirusWall for Windows NT 3.6 Trend Micro InterScan VirusWall for Windows NT 3.5 Trend Micro InterScan VirusWall for Windows NT 3.4 Trend Micro InterScan VirusWall for Unix 3.6 x Trend Micro InterScan VirusWall for Unix 3.0.1 Trend Micro Interscan Viruswall (Solaris) 3.6 Trend Micro Interscan Viruswall (Linux) 3.6 Trend Micro Interscan Viruswall (Linux) 3.0.1 Trend Micro Interscan Viruswall (HP-UX) 3.6 Trend Micro InterScan VirusWall 3.52 Trend Micro InterScan VirusWall 3.32 Trend Micro InterScan VirusWall 3.8 Build 1130 Trend Micro InterScan VirusWall 3.7 Build 1190 Trend Micro InterScan VirusWall 3.7 Trend Micro InterScan VirusWall 3.6 Build 1182 Trend Micro InterScan VirusWall 3.6 Build 1166 Trend Micro InterScan VirusWall 3.6 Trend Micro InterScan VirusWall 3.3 Trend Micro InterScan VirusWall 3.2.3 Trend Micro InterScan VirusWall 3.0.1 |
| Not Vulnerable: | |
Discussion
Trend Micro Scanning Engine Report Generation HTML Injection Vulnerability
Trend Micro's scanning engine is reportedly affected by an HTML injection vulnerability in its report generation feature. This issue is due to a failure to properly sanitize user-supplied before including it in a HTML report.
It has been speculated that the offending HTML alert reports run from the local zone on the affected computer, although this has not been verified.
This issue may be exploited by a remote attacker to execute arbitrary HTML or script code on an affected computer; potentially resulting in unauthorized access. Other attackers are also possible.
Trend Micro's scanning engine is reportedly affected by an HTML injection vulnerability in its report generation feature. This issue is due to a failure to properly sanitize user-supplied before including it in a HTML report.
It has been speculated that the offending HTML alert reports run from the local zone on the affected computer, although this has not been verified.
This issue may be exploited by a remote attacker to execute arbitrary HTML or script code on an affected computer; potentially resulting in unauthorized access. Other attackers are also possible.
Exploit / POC
Trend Micro Scanning Engine Report Generation HTML Injection Vulnerability
No exploit is currently available to leverage this issue. A proof of concept has been released publically.
No exploit is currently available to leverage this issue. A proof of concept has been released publically.
Solution / Fix
Trend Micro Scanning Engine Report Generation HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Trend Micro Scanning Engine Report Generation HTML Injection Vulnerability
References:
References: