CVE-2018-10350
25.05.2018, 15:29
A SQL injection remote code execution vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw within the handling of parameters provided to wcs\_bwlists\_handler.php. Authentication is required in order to exploit this vulnerability.
Vendor | Product | Version |
---|---|---|
trendmicro | smart_protection_server | 3.0 |
trendmicro | smart_protection_server | 3.1 |
trendmicro | smart_protection_server | 3.2 |
trendmicro | smart_protection_server | 3.3 |
𝑥
= Vulnerable software versions