Trend Micro Control Manager(TMCM)是美国趋势科技(Trend Micro)公司的一套集成了威胁检测和数据保护的管理中心软件。 TMCM 6.0版本中的‘ID_QUERY_COMMAND_TRACKING_USER_ID’参数的处理存在SQL注入漏洞,该漏洞源于程序在使用SQL查询语句之前,没有正确过滤用户提交的字符串。远程攻击者可利用该漏洞在Network Service账户的上下文中执行代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Trend Micro | Trend Micro Control Manager | 6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2018-3600 | Trend Micro Control Manager 信息泄露漏洞 | |
| CVE-2018-3601 | Trend Micro Control Manager 安全漏洞 | |
| CVE-2018-3602 | Trend Micro Control Manager SQL注入漏洞 | |
| CVE-2018-3604 | Trend Micro Control Manager SQL注入漏洞 | |
| CVE-2018-3605 | Trend Micro Control Manager SQL注入漏洞 | |
| CVE-2018-3606 | Trend Micro Control Manager SQL注入漏洞 | |
| CVE-2018-3607 | Trend Micro Control Manager SQL注入漏洞 |
No comments yet