CVE-2016-4351
Trend Micro Mail Encryption Gateway SQL Injection Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
SQL injection vulnerability in the authentication functionality in Trend Micro Email Encryption Gateway (TMEEG) 5.5 before build 1107 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Vulnerabilidad de inyección SQL en la funcionalidad de autenticación en Trend Micro Email Encryption Gateway (TMEEG) 5.5 en versiones anteriores a build 1107 permite a atacantes remotos ejecutar comandos SQL arbitrarios a través de vectores no especificados.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Trend Micro Email Encryption Gateway. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the authentication functionality. The issue lies in the failure to sanitize user-supplied input prior to executing a SQL statement. An attacker could leverage this vulnerability to bypass authentication or execute code under the context of the database.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-04-28 CVE Published
- 2016-04-29 CVE Reserved
- 2024-08-05 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.zerodayinitiative.com/advisories/ZDI-16-248 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://esupport.trendmicro.com/solution/en-US/1114060.aspx | 2021-09-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Trendmicro Search vendor "Trendmicro" | Email Encryption Gateway Search vendor "Trendmicro" for product "Email Encryption Gateway" | <= 5.5 Search vendor "Trendmicro" for product "Email Encryption Gateway" and version " <= 5.5" | - |
Affected
|