CVE-2020-8604
HIGHTrend Micro InterScan Web Security Virtual Appliance 6.5 - Path Traversal
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-8604.
PoCs published by Mehmet Ince <[email protected]>, including Metasploit module exploits/linux/http/trendmicro_websecurity_exec.
AI-analyzed exploit summary This Metasploit module exploits a chain of vulnerabilities (CVE-2020-8604, CVE-2020-8605, CVE-2020-8606) in Trend Micro Web Security Virtual Appliance to achieve unauthenticated remote code execution as root. It leverages a proxy service flaw to extract session IDs and a command injection vulnerability in the LogSettingHandler class.
Description
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on affected installations.
Exploits (1)
This Metasploit module exploits a chain of vulnerabilities (CVE-2020-8604, CVE-2020-8605, CVE-2020-8606) in Trend Micro Web Security Virtual Appliance to achieve unauthenticated remote code execution as root. It leverages a proxy service flaw to extract session IDs and a command injection vulnerability in the LogSettingHandler class.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N