Arbitrary logs location in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to change location of log files and be manipulated to execute arbitrary commands and attain command execution on a vulnerable system.
References
Link | Resource |
---|---|
https://www.coresecurity.com/advisories/trend-micro-email-encryption-gateway-multiple-vulnerabilities | Exploit Technical Description Third Party Advisory |
https://success.trendmicro.com/solution/1119349 | Patch Vendor Advisory |
https://www.exploit-db.com/exploits/44166/ | Exploit Third Party Advisory VDB Entry |
Configurations
Information
Published : 2018-03-15 12:29
Updated : 2019-10-02 17:03
NVD link : CVE-2018-6222
Mitre link : CVE-2018-6222
JSON object : View
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Products Affected
trendmicro
- email_encryption_gateway