CVE-2017-11392
HIGHTrend Micro InterScan Messaging Security Virtual Appliance 9.0-9.1 - RCE via modTMCSS Proxy
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-11392.
PoCs published by mr_me <[email protected]>, Mehmet Ince <[email protected]>, including Metasploit module exploits/linux/http/trendmicro_imsva_widget_exec.
AI-analyzed exploit summary This Metasploit module exploits an authentication bypass (CVE-2017-11391) and command injection (CVE-2017-11392) in Trend Micro IMSVA. It extracts a JSESSIONID from a publicly accessible log file, bypasses authentication, and executes arbitrary commands via the proxy_controller.php endpoint.
Description
Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the "T" parameter within modTMCSS Proxy. Formerly ZDI-CAN-4745.
Exploits (1)
This Metasploit module exploits an authentication bypass (CVE-2017-11391) and command injection (CVE-2017-11392) in Trend Micro IMSVA. It extracts a JSESSIONID from a publicly accessible log file, bypasses authentication, and executes arbitrary commands via the proxy_controller.php endpoint.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H