CVE-2018-3603
- EPSS 4.55%
- Published 09.02.2018 22:29:00
- Last modified 21.11.2024 04:05:45
A CGGIServlet SQL injection remote code execution (RCE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.
CVE-2018-3601
- EPSS 5.73%
- Published 09.02.2018 22:29:00
- Last modified 21.11.2024 04:05:44
A password hash usage authentication bypass vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to bypass authentication on vulnerable installations.
CVE-2018-3600
- EPSS 0.31%
- Published 09.02.2018 22:29:00
- Last modified 21.11.2024 04:05:44
A external entity processing information disclosure (XXE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to disclose sensitive information on vulnerable installations.
CVE-2016-6220
- EPSS 0.53%
- Published 07.08.2017 20:29:01
- Last modified 20.04.2025 01:37:25
Information Disclosure vulnerability in the Dashboard and Error Pages in Trend Micro Control Manager SP3 6.0.
CVE-2017-11383
- EPSS 7.24%
- Published 02.08.2017 21:29:00
- Last modified 20.04.2025 01:37:25
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x1b07 due to lack of proper user input validation in cmdHandlerTVCSCommander.dll. Formerly ZDI-CAN-4560.
CVE-2017-11390
- EPSS 0.57%
- Published 02.08.2017 21:29:00
- Last modified 20.04.2025 01:37:25
XML external entity (XXE) processing vulnerability in Trend Micro Control Manager 6.0, if exploited, could lead to information disclosure. Formerly ZDI-CAN-4706.
CVE-2017-11389
- EPSS 7.67%
- Published 02.08.2017 21:29:00
- Last modified 20.04.2025 01:37:25
Directory traversal vulnerability in Trend Micro Control Manager 6.0 allows remote code execution by attackers able to drop arbitrary files in a web-facing directory. Formerly ZDI-CAN-4684.
CVE-2017-11388
- EPSS 7.77%
- Published 02.08.2017 21:29:00
- Last modified 20.04.2025 01:37:25
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when RestfulServiceUtility.NET.dll doesn't properly validate user provided strings before constructing SQL queries. Formerly ZDI-CAN-4639 and ZDI-CAN-4638.
CVE-2017-11387
- EPSS 2.09%
- Published 02.08.2017 21:29:00
- Last modified 20.04.2025 01:37:25
Authentication Bypass in Trend Micro Control Manager 6.0 causes Information Disclosure when authentication validation is not done for functionality that can change debug logging level. Formerly ZDI-CAN-4512.
CVE-2017-11386
- EPSS 7.24%
- Published 02.08.2017 21:29:00
- Last modified 20.04.2025 01:37:25
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x4707 due to lack of proper user input validation in cmdHandlerNewReportScheduler.dll. Formerly ZDI-CAN-4549.