CVEs (12)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Trendmicro 1Threat Discovery Appliance May 13, 2026 Apr 28, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Directory traversal vulnerability in upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via a .. (dot dot) in the dID parameter. |
1Trendmicro 1Threat Discovery Appliance May 13, 2026 Apr 28, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 log_query_system.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter. |
1Trendmicro 1Threat Discovery Appliance May 13, 2026 Apr 28, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 log_query.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter. |
1Trendmicro 1Threat Discovery Appliance May 13, 2026 Apr 28, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 log_query_dlp.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter. |
1Trendmicro 1Threat Discovery Appliance May 13, 2026 Apr 28, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 log_query_dae.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter. |
1Trendmicro 1Threat Discovery Appliance May 13, 2026 Apr 28, 2017 N/A· v4 7.3 HIGH· v3 6.0 MEDIUM· v2 The hotfix_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the file name of an uploaded file. |
1Trendmicro 1Threat Discovery Appliance May 13, 2026 Apr 28, 2017 N/A· v4 7.3 HIGH· v3 6.0 MEDIUM· v2 dlp_policy_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via an archive file containing a symlink to /eng_ptn_stores/prod/sensorSD...Show more |
1Trendmicro 1Threat Discovery Appliance May 13, 2026 Apr 28, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 detected_potential_files.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id paramete...Show more |
1Trendmicro 1Threat Discovery Appliance May 13, 2026 Apr 28, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 admin_sys_time.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the timezone parameter. |
1Trendmicro 1Threat Discovery Appliance May 13, 2026 Apr 28, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which allows remote attackers to bypass authentication by guessing the value. |
1Trendmicro 1Threat Discovery Appliance May 13, 2026 Apr 12, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can be used to bypass au...Show more |
1Trendmicro 1Threat Discovery Appliance May 13, 2026 Apr 12, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.cgi interface. |