hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to execute arbitrary code via shell metacharacters in the filename parameter of the Content-Disposition header.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2016-06-30 09:59
Updated : 2016-11-28 12:29
NVD link : CVE-2016-5840
Mitre link : CVE-2016-5840
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
trend_micro
- deep_discovery_inspector