HTTP: Trend Micro Control Manager ad hoc query Module SQL Injection

This signature detects attempts to exploit known vulnerability against Trend Micro Control Manager. An attacker can exploit this vulnerability to submit crafted SQL queries to the underlying database.

Extended Description

SQL injection vulnerability in the ad hoc query module in Trend Micro Control Manager (TMCM) before 5.5.0.1823 and 6.0 before 6.0.0.1449 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Affected Products

Trend_micro control_manager

References

BugTraq: 55706

CVE: CVE-2012-2998

Short Name
HTTP:TRENDMICRO-CTRLMGR-SQLINJ
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2012-2998 Control Injection Manager Micro Module SQL Trend ad bid:55706 hoc query
Release Date
01/08/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Trend_micro

CVSS Score

7.5

Found a potential security threat?