CRLF injection vulnerability in Trend Micro Worry-Free Business Security Service 5.x and Worry-Free Business Security 9.0 allows remote attackers to inject arbitrary HTTP headers and conduct cross-site scripting (XSS) attacks via unspecified vectors.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://jvn.jp/en/jp/JVN48847535/index.html | third party advisory vendor advisory |
http://esupport.trendmicro.com/solution/ja-JP/1114102.aspx | vendor advisory |
http://jvndb.jvn.jp/jvndb/JVNDB-2016-000089 | vendor advisory third party advisory vdb entry |