The hotfix_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the file name of an uploaded file.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2017-04-28T19:00:00

Updated: 2024-08-06T02:27:40.807Z

Reserved: 2016-10-10T00:00:00

Link: CVE-2016-8588

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-04-28T19:59:00.297

Modified: 2017-05-10T17:49:22.737

Link: CVE-2016-8588

cve-icon Redhat

No data.