Roberto Suggi Liverani @malerisch

2 exploits Active since Apr 2017
CVE-2016-7552 METASPLOIT CRITICAL ruby WORKING POC
Trend Micro Threat Discovery Appliance 2.6.1062r1 - Path Traversal & File Deletion via Session ID
On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can be used to bypass authentication or cause a DoS.
CVSS 9.8
CVE-2016-7547 METASPLOIT CRITICAL ruby WORKING POC
Trend Micro Threat Discovery Appliance admin_sys_time.cgi Remote Command Execution
A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.cgi interface.
CVSS 9.8