Vulnerability Description
Multiple directory traversal vulnerabilities in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allow remote attackers to read and delete arbitrary files via the tmpfname parameter to (1) log_mgt_adhocquery_ajaxhandler.php, (2) log_mgt_ajaxhandler.php, (3) log_mgt_ajaxhandler.php or (4) tf parameter to wcs_bwlists_handler.php.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trendmicro | Smart Protection Server | 2.5 |
Related Weaknesses (CWE)
References
- https://qkaiser.github.io/pentesting/trendmicro/2016/08/08/trendmicro-sps/ExploitTechnical DescriptionThird Party Advisory
- https://success.trendmicro.com/solution/1114913MitigationPatchVendor Advisory
- https://qkaiser.github.io/pentesting/trendmicro/2016/08/08/trendmicro-sps/ExploitTechnical DescriptionThird Party Advisory
- https://success.trendmicro.com/solution/1114913MitigationPatchVendor Advisory
FAQ
What is CVE-2016-6269?
CVE-2016-6269 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Multiple directory traversal vulnerabilities in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allow remote attackers to read and delete ar...
How severe is CVE-2016-6269?
CVE-2016-6269 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-6269?
Check the references section above for vendor advisories and patch information. Affected products include: Trendmicro Smart Protection Server.