CVE-2016-5840: Input Validation
hotfixupload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to execute arbitrary code via shell metacharacters in the filename parameter of the Content-Disposition header.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5840?
CVE-2016-5840 has a high severity rating due to its potential to allow remote code execution.
How do I fix CVE-2016-5840?
You can fix CVE-2016-5840 by updating to the latest version of Trend Micro Deep Discovery Inspector that addresses this vulnerability.
What versions of Trend Micro Deep Discovery Inspector are affected by CVE-2016-5840?
CVE-2016-5840 affects Trend Micro Deep Discovery Inspector versions 3.7, 3.8 SP1, and 3.8 SP2.
What type of attack is facilitated by CVE-2016-5840?
CVE-2016-5840 facilitates remote code execution attacks through shell metacharacters in crafted requests.
Who can exploit CVE-2016-5840?
Remote administrators with access to the system can potentially exploit CVE-2016-5840 to execute arbitrary code.