ZeroHour

CVE-2016-5840

PoC
CVSS 3.0
7.2 high
EPSS
8%p94
Published
()
Modified
Description

hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to execute arbitrary code via shell metacharacters in the filename parameter of the Content-Disposition header.

Vendors
trend micro
Products
deep discovery inspector
Weakness
CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.