CVE-2017-11391
HIGHTrend Micro InterScan Messaging Security Virtual Appliance 9.0-9.1 - RCE via modTMCSS Proxy
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-11391.
PoCs published by mr_me <[email protected]>, Mehmet Ince <[email protected]>, including Metasploit module exploits/linux/http/trendmicro_imsva_widget_exec.
AI-analyzed exploit summary This Metasploit module exploits an authentication bypass and command injection vulnerability in Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA). It extracts a JSESSIONID from a publicly accessible log file and uses it to execute arbitrary commands via a vulnerable PHP endpoint.
Description
Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the "t" parameter within modTMCSS Proxy. Formerly ZDI-CAN-4744.
Exploits (1)
This Metasploit module exploits an authentication bypass and command injection vulnerability in Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA). It extracts a JSESSIONID from a publicly accessible log file and uses it to execute arbitrary commands via a vulnerable PHP endpoint.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H