CVE-2008-2437

Stack-based buffer overflow in cgiRecvFile.exe in Trend Micro OfficeScan 7.3 patch 4 build 1362 and other builds, OfficeScan 8.0 and 8.0 SP1, and Client Server Messaging Security 3.6 allows remote attackers to execute arbitrary code via an HTTP request containing a long ComputerName parameter.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
flexeraCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
VendorProductVersion
trend_microclient-server-messaging_security
2.0
trend_microclient-server-messaging_security
3.0
trend_microclient-server-messaging_security
3.5
trend_microclient-server-messaging_security
3.6
trend_microofficescan
7.0
trend_microofficescan
7.3
trend_microofficescan
7.3:patch_4
trend_microofficescan
8.0
trend_microofficescan
8.0:sp1
𝑥
= Vulnerable software versions
References