Trend Micro Smart Protection Server wcs_bwlists_handler.php Command Injection

A remote command execution vulnerability exists in the wcs_bwlists_handler.php script of Trend Micro Smart Protection Server. The vulnerability is due to insufficient validation of user-supplied input. A remote, authenticated attacker could exploit this vulnerability by providing crafted input to the vulnerable system.

from Check Point Update Services Advisories http://ift.tt/2ren9B5

No comments:

Post a Comment

Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading

Cybersecurity researchers have uncovered a new phishing campaign that exploits social media private messages to propagate malicious payloads...