Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-14096. PoCs published by CoreLabs.
AI-analyzed exploit summary The exploit demonstrates session hijacking via log file disclosure and remote command execution via cron job injection in Trend Micro Smart Protection Server. It leverages CVE-2017-11398 and CVE-2017-14094 to achieve unauthenticated RCE.
Description
A stored cross site scripting (XSS) vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to execute a malicious payload on vulnerable systems.
Exploits (1)
The exploit demonstrates session hijacking via log file disclosure and remote command execution via cron job injection in Trend Micro Smart Protection Server. It leverages CVE-2017-11398 and CVE-2017-14094 to achieve unauthenticated RCE.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N