Trend Micro WebReputation API URI Security Bypass Vulnerability
BID:46864
Info
Trend Micro WebReputation API URI Security Bypass Vulnerability
| Bugtraq ID: | 46864 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 14 2011 12:00AM |
| Updated: | Mar 14 2011 12:00AM |
| Credit: | DcLabs Security Research Group |
| Vulnerable: |
Trend Micro WebReputation API 10.5 Trend Micro WebReputation API 0 |
| Not Vulnerable: | |
Discussion
Trend Micro WebReputation API URI Security Bypass Vulnerability
Trend Micro WebReputation API is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass the filter included in the download mechanism. Successful exploits may cause victims to download malicious files onto affected computers.
This issue affects WebReputation API 10.5; other versions may also be vulnerable.
Trend Micro WebReputation API is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass the filter included in the download mechanism. Successful exploits may cause victims to download malicious files onto affected computers.
This issue affects WebReputation API 10.5; other versions may also be vulnerable.
Exploit / POC
Trend Micro WebReputation API URI Security Bypass Vulnerability
The following proof of concept URI is available:
http://www.example.com/dist/nmap-5.51-setup.exe?
The following proof of concept URI is available:
http://www.example.com/dist/nmap-5.51-setup.exe?
Solution / Fix
Trend Micro WebReputation API URI Security Bypass Vulnerability
Solution:
The vendor released an update. Please see the references for details.
Solution:
The vendor released an update. Please see the references for details.
References
Trend Micro WebReputation API URI Security Bypass Vulnerability
References:
References:
- Trend Micro Homepage (Trend Micro)