2 results (0.002 seconds)

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 1

A Reflected Cross-Site Scripting (XSS) vulnerability in Trend Micro Deep Discovery Inspector 3.85 and below could allow an attacker to bypass CSRF protection and conduct an attack on vulnerable installations. An attacker must be an authenticated user in order to exploit the vulnerability. Una vulnerabilidad de Cross-Site Scripting (XSS) reflejado en Trend Micro Deep Discovery Inspector en versiones 3.85 y anteriores podría permitir que un atacante omita la protección CSRF y lleve a cabo un ataque en instalaciones vulnerables. El atacante debe ser un usuario autenticado para explotar esta vulnerabilidad. • https://github.com/nixwizard/CVE-2018-15365 https://success.trendmicro.com/solution/1121079 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.0EPSS: 3%CPEs: 3EXPL: 1

hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to execute arbitrary code via shell metacharacters in the filename parameter of the Content-Disposition header. hotfix_upload.cgi en Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81) y 3.8 SP2 (3.82) permite a administradores remotos ejecutar código arbitrario a través de metacaracteres de shell en el parámetro filename de la cabecera Content-Disposition. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Trend Micro Deep Discovery. Authentication is required to exploit this vulnerability. The specific flaw exists within hotfix_upload.cgi. The vulnerability is caused by the lack of input validation before passing a remotely supplied string to a system call. By sending a crafted request to a vulnerable system, a remote attacker can exploit this vulnerability to execute arbitrary code in the context of root. • https://www.exploit-db.com/exploits/40180 http://esupport.trendmicro.com/solution/en-US/1114281.aspx http://jvn.jp/en/jp/JVN55428526/index.html http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000103.html http://www.zerodayinitiative.com/advisories/ZDI-16-373 • CWE-20: Improper Input Validation •