Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the T parameter within Proxy.php. Formerly ZDI-CAN-4544.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/100130 | vdb entry third party advisory |
https://success.trendmicro.com/solution/1117769 | patch vendor advisory mitigation |
https://www.exploit-db.com/exploits/42971/ | exploit |
http://www.zerodayinitiative.com/advisories/ZDI-17-521 | vdb entry third party advisory |