CVE-2016-6269
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Multiple directory traversal vulnerabilities in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allow remote attackers to read and delete arbitrary files via the tmpfname parameter to (1) log_mgt_adhocquery_ajaxhandler.php, (2) log_mgt_ajaxhandler.php, (3) log_mgt_ajaxhandler.php or (4) tf parameter to wcs_bwlists_handler.php.
Varias vulnerabilidades de salto de directorio en Trend Micro Smart Protection Server 2.5 en versiones anteriores a build 2200, 2.6 en versiones anteriores a build 2106 y 3.0 en versiones anteriores a build 1330 permiten a atacantes remotos leer y borrar archivos arbitrarios a través del parámetro tmpfname para (1) log_mgt_adhocquery_ajaxhandler.php, (2) log_mgt_ajaxhandler .php, (3) log_mgt_ajaxhandler.php o (4) del parámetro tf para wcs_bwlists_handler.php.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-07-21 CVE Reserved
- 2017-01-30 CVE Published
- 2023-11-21 EPSS Updated
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://qkaiser.github.io/pentesting/trendmicro/2016/08/08/trendmicro-sps | 2024-08-06 |
URL | Date | SRC |
---|---|---|
https://success.trendmicro.com/solution/1114913 | 2021-09-09 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Trendmicro Search vendor "Trendmicro" | Smart Protection Server Search vendor "Trendmicro" for product "Smart Protection Server" | 2.5 Search vendor "Trendmicro" for product "Smart Protection Server" and version "2.5" | - |
Affected
| ||||||
Trendmicro Search vendor "Trendmicro" | Smart Protection Server Search vendor "Trendmicro" for product "Smart Protection Server" | 2.6 Search vendor "Trendmicro" for product "Smart Protection Server" and version "2.6" | - |
Affected
| ||||||
Trendmicro Search vendor "Trendmicro" | Smart Protection Server Search vendor "Trendmicro" for product "Smart Protection Server" | 3.0 Search vendor "Trendmicro" for product "Smart Protection Server" and version "3.0" | - |
Affected
|