CVE-2016-6270
30.01.2017, 22:59
The handle_certificate function in /vmi/manager/engine/management/commands/apns_worker.py in Trend Micro Virtual Mobile Infrastructure before 5.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the password to api/v1/cfg/oauth/save_identify_pfx/.
Vendor | Product | Version |
---|---|---|
trendmicro | virtual_mobile_infrastructure | 5.0 |
𝑥
= Vulnerable software versions
References