CVE-2016-6269

CWE-22Path Traversal3 documents3 sources
Severity
9.1CRITICAL
EPSS
1.9%
top 16.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 30
Latest updateMay 13

Description

Multiple directory traversal vulnerabilities in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allow remote attackers to read and delete arbitrary files via the tmpfname parameter to (1) log_mgt_adhocquery_ajaxhandler.php, (2) log_mgt_ajaxhandler.php, (3) log_mgt_ajaxhandler.php or (4) tf parameter to wcs_bwlists_handler.php.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-74wc-vcgr-2498: Multiple directory traversal vulnerabilities in Trend Micro Smart Protection Server 22022-05-13
CVEList
CVE-2016-6269: Multiple directory traversal vulnerabilities in Trend Micro Smart Protection Server 22017-01-30
CVE-2016-6269 (CRITICAL CVSS 9.1) | Multiple directory traversal vulner | cvebase.io