CVE-2017-11388: SQL Injection
Published Aug 2, 2017
·Updated
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when RestfulServiceUtility.NET.dll doesn't properly validate user provided strings before constructing SQL queries. Formerly ZDI-CAN-4639 and ZDI-CAN-4638.
Affected Software
1 affected component
trendmicro Control Manager=6.0
Remediation
Patch Available
Event History
Aug 2, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11388?
CVE-2017-11388 is classified as a critical severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2017-11388?
To fix CVE-2017-11388, update to the latest version of Trend Micro Control Manager that addresses the SQL injection vulnerability.
3
What type of vulnerability is CVE-2017-11388?
CVE-2017-11388 is an SQL Injection vulnerability that can lead to remote code execution.
4
Which software is affected by CVE-2017-11388?
CVE-2017-11388 affects Trend Micro Control Manager version 6.0.
5
Can CVE-2017-11388 be exploited remotely?
Yes, CVE-2017-11388 can be exploited remotely due to insufficient input validation in its web services.