First published: Mon Oct 09 2006(Updated: )
Trend Micro OfficeScan 6.0 in Client/Server/Messaging (CSM) Suite for SMB 2.0 before 6.0.0.1385, and OfficeScan Corporate Edition (OSCE) 6.5 before 6.5.0.1418, 7.0 before 7.0.0.1257, and 7.3 before 7.3.0.1053 allow remote attackers to delete files via a modified filename parameter in a certain HTTP request that invokes the OfficeScan CGI program.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro OfficeScan XG | =6.0 | |
Trend Micro OfficeScan XG | =corporate_6.5 | |
Trend Micro OfficeScan XG | =corporate_7.0 | |
Trend Micro OfficeScan XG | =corporate_7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5212 has a medium severity level, allowing remote attackers to delete files.
To fix CVE-2006-5212, update Trend Micro OfficeScan to the latest version specified in the vendor's security patches.
CVE-2006-5212 affects Trend Micro OfficeScan 6.0, Corporate Edition 6.5, 7.0, and 7.3 before specific patch levels.
CVE-2006-5212 facilitates remote file deletion attacks via a modified filename parameter in an HTTP request.
If you are using an affected version of Trend Micro OfficeScan without the necessary updates, your system is vulnerable to CVE-2006-5212.