Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the tr parameter within Proxy.php. Formerly ZDI-CAN-4543.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-3020 | Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the tr parameter within Proxy.php. Formerly ZDI-CAN-4543. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: trendmicro
Published:
Updated: 2024-09-16T23:45:51.827Z
Reserved: 2017-07-17T00:00:00
Link: CVE-2017-11393
No data.
Status : Deferred
Published: 2017-08-03T15:29:00.403
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-11393
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD