CVE-2016-5840
Last modified
CVE-2016-5840 is a vulnerability of currently unknown severity. hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to execute arbitrary code via shell metacharacters in the filename parameter of the Content-Disposition header.. EPSS estimates a 7.77% chance of exploitation in the next 30 days.
Description
hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to execute arbitrary code via shell metacharacters in the filename parameter of the Content-Disposition header.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Trend Micro | Deep Discovery Inspector | 3.7 |
| Trend Micro | Deep Discovery Inspector | 3.81 |
| Trend Micro | Deep Discovery Inspector | 3.82 |
References
- http://esupport.trendmicro.com/solution/en-US/1114281.aspxVendor Advisory
- https://www.exploit-db.com/exploits/40180/Exploit, Third Party Advisory
- http://esupport.trendmicro.com/solution/en-US/1114281.aspxVendor Advisory
- https://www.exploit-db.com/exploits/40180/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-5840?
How severe is CVE-2016-5840?
How do I fix CVE-2016-5840?
Are you affected by CVE-2016-5840?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
