Trendmicro Interscan Messaging Security Suite vulnerabilities
3 known vulnerabilities affecting trendmicro/interscan_messaging_security_suite.
Total CVEs
3
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2012-2996MEDIUMCVSS 6.8PoCv7.12012-09-17
CVE-2012-2996 [MEDIUM] CWE-352 CVE-2012-2996: Cross-site request forgery (CSRF) vulnerability in saveAccountSubTab.imss in Trend Micro InterScan M
Cross-site request forgery (CSRF) vulnerability in saveAccountSubTab.imss in Trend Micro InterScan Messaging Security Suite 7.1-Build_Win32_1394 allows remote attackers to hijack the authentication of administrators for requests that create admin accounts via a saveAuth action.
nvd
CVE-2012-2995MEDIUMCVSS 4.3PoCv7.12012-09-17
CVE-2012-2995 [MEDIUM] CWE-79 CVE-2012-2995: Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro InterScan Messaging Security Suit
Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro InterScan Messaging Security Suite 7.1-Build_Win32_1394 allow remote attackers to inject arbitrary web script or HTML via (1) the wrsApprovedURL parameter to addRuleAttrWrsApproveUrl.imss or (2) the src parameter to initUpdSchPage.imss.
nvd
CVE-2006-1380HIGHCVSS 7.2v5.52006-03-24
CVE-2006-1380 [HIGH] CWE-264 CVE-2006-1380: ISNTSmtp directory in Trend Micro InterScan Messaging Security Suite (IMSS) 5.5 build 1183 and possi
ISNTSmtp directory in Trend Micro InterScan Messaging Security Suite (IMSS) 5.5 build 1183 and possibly other versions before 5.7.0.1121, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying ISNTSysMonitor.exe.
nvd