Trend Micro Control Manager ‘ad hoc query’模块SQL注入漏洞

漏洞信息详情

Trend Micro Control Manager ‘ad hoc query’模块SQL注入漏洞

漏洞简介

Trend Micro Control Manager(TMCM)是美国趋势科技(Trend Micro)公司的一套集成了威胁检测和数据保护的管理中心软件。

Trend Micro Control Manager (TMCM)5.5.0.1823之前版本和6.0.0.1449之前的6.0版本中的‘ad hoc query’模块中存在SQL注入漏洞。远程攻击者可利用该漏洞通过未明漏洞执行任意SQL命令。

漏洞公告

目前厂商已经发布了升级补丁以修复此安全问题,补丁获取链接:

http://jvn.jp/en/jp/JVN42014489/index.html

参考网址

来源:US-CERT Vulnerability Note: VU#950795

名称: VU#950795

链接:http://www.kb.cert.org/vuls/id/950795

来源: www.trendmicro.com

链接:http://www.trendmicro.com/ftp/documentation/readme/readme_critical_patch_tmcm60_patch1_1449.txt

来源: www.trendmicro.com

链接:http://www.trendmicro.com/ftp/documentation/readme/readme_critical_patch_TMCM55_1823.txt

来源: www.spentera.com

链接:http://www.spentera.com/2012/09/trend-micro-control-manager-sql-injection-vulnerability/

来源: JVNDB

名称: JVNDB-2012-000090

链接:http://jvndb.jvn.jp/jvndb/JVNDB-2012-000090

来源: JVN

名称: JVN#42014489

链接:http://jvn.jp/en/jp/JVN42014489/index.html

来源: esupport.trendmicro.com

链接:http://esupport.trendmicro.com/solution/en-us/1061043.aspx

来源:SECUNIA

名称:50748

链接:http://secunia.com/advisories/50748

来源:SECUNIA

名称:50760

链接:http://secunia.com/advisories/50760

来源: BID

名称: 55706

链接:http://www.securityfocus.com/bid/55706
来源:NSFOCUS
名称:20890
链接:http://www.nsfocus.net/vulndb/20890

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享