CVE-2016-6266: Input Validation
cccaajaxhandler.php in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) host or (2) apikey parameter in a register action, (3) enable parameter in a savestting action, or (4) host or (5) apikey parameter in a testconnection action.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6266?
CVE-2016-6266 has a high severity level due to the potential for remote command execution by authenticated users.
How do I fix CVE-2016-6266?
To fix CVE-2016-6266, update your Trend Micro Smart Protection Server to version 2.5 build 2200, 2.6 build 2106, or 3.0 build 1330 or later.
What are the affected versions in CVE-2016-6266?
CVE-2016-6266 affects Trend Micro Smart Protection Server versions 2.5, 2.6, and 3.0 prior to specified builds.
What type of vulnerability is CVE-2016-6266?
CVE-2016-6266 is a command injection vulnerability that allows attackers to execute arbitrary commands.
Can CVE-2016-6266 be exploited remotely?
Yes, CVE-2016-6266 can be exploited remotely by authenticated users through the web interface of the affected software.