CVE-2017-9032

MEDIUM

Trend Micro ServerProtect for Linux <3.0 - XSS

Title source: llm
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allow remote attackers to inject arbitrary web script or HTML via the (1) T1 or (2) tmLastConfigFileModifiedDate parameter to log_management.cgi.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038548
Patch, Vendor Advisory x_refsource_confirm
https://success.trendmicro.com/solution/1117411
Exploit, Technical Description, Third Party Advisory x_refsource_misc
https://www.coresecurity.com/advisories/trend-micro-serverprotect-multiple-vulnerabilities
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2017/May/91

Scores

CVSS v3 6.1
EPSS 0.0124
EPSS Percentile 79.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
trendmicro/serverprotect 3.0
Published May 26, 2017
Tracked Since Feb 18, 2026