9
CVSSv2

CVE-2016-5840

Published: 30/06/2016 Updated: 28/11/2016
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 905
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to execute arbitrary code via shell metacharacters in the filename parameter of the Content-Disposition header.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

trend micro deep discovery inspector 3.7

trend micro deep discovery inspector 3.82

trend micro deep discovery inspector 3.81

Exploits

Version: TDA 261062r1 Summary: The hotfix_uploadcgi file contains a flaw allowing a user to execute commands under the context of the root user Details: The hotfix_uploadcgi file is used to upload files (hot fixes) Below is a sample of the upload function being used: POST /cgi-bin/hotfix_uploadcgi?sID=hotfix_temp HTTP/11 Accept: image/ ...