Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the tr parameter within Proxy.php. Formerly ZDI-CAN-4543.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://success.trendmicro.com/solution/1117769 | patch vendor advisory mitigation |
http://www.zerodayinitiative.com/advisories/ZDI-17-522 | third party advisory vdb entry |
http://www.securityfocus.com/bid/100127 | vdb entry |