Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:SQL:CVE-2018-3604-SQL-INJ

Severity

Major

Recommended

Yes

Recommended Action

Drop

Category

HTTP

Keywords

Trend MIcro Control Manager sCloudService GetPassword SQL Injection

Release Date

2018/06/21

Update Number

3076

Supported Platforms

idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: Trend MIcro Control Manager sCloudService GetPassword SQL Injection


This signature detects attempts to exploit a known vulnerability against Trend Micro Control Manager. A successful attack can lead to arbitrary code execution.

Extended Description

GetXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary code on vulnerable installations.

Affected Products

  • Trendmicro control_manager 6.0

References

  • CVE: CVE-2018-3604
  • URL: http://www.zerodayinitiative.com/advisories/zdi-18-067/
  • URL: https://success.trendmicro.com/solution/1119158

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out