Back to search
CVE-2017-11391
Published: Aug 3, 2017
Modified: Sep 17, 2024
PUBLISHED
Description
Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the "t" parameter within modTMCSS Proxy. Formerly ZDI-CAN-4744.
| Vendor | Product | Versions |
|---|---|---|
Trend Micro | Trend Micro InterScan Messaging Security Virtual Appliance | affected 9.0,9.1 |
References
100075
vdb-entry
x_refsource_BID
https://success.trendmicro.com/solution/1117723
x_refsource_MISC
http://www.zerodayinitiative.com/advisories/ZDI-17-502
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now