PT-2006-5947 · Trend Micro · Trend Micro Officescan+2
Published
2006-10-09
·
Updated
2011-03-08
·
CVE-2006-5212
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Trend Micro OfficeScan versions 6.0 through 6.0.0.1384
Trend Micro OfficeScan Corporate Edition (OSCE) versions 6.5 through 6.5.0.1417
Trend Micro OfficeScan Corporate Edition (OSCE) versions 7.0 through 7.0.0.1256
Trend Micro OfficeScan Corporate Edition (OSCE) versions 7.3 through 7.3.0.1052
Description
The issue allows remote attackers to delete files by modifying the filename parameter in a certain HTTP request. This request invokes the OfficeScan CGI program, enabling unauthorized file deletion.
Recommendations
For Trend Micro OfficeScan version 6.0, update to version 6.0.0.1385 or later.
For Trend Micro OfficeScan Corporate Edition (OSCE) version 6.5, update to version 6.5.0.1418 or later.
For Trend Micro OfficeScan Corporate Edition (OSCE) version 7.0, update to version 7.0.0.1257 or later.
For Trend Micro OfficeScan Corporate Edition (OSCE) version 7.3, update to version 7.3.0.1053 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trend Micro Officescan
Trend Micro Officescan Corporate Edition
Trend Micro Officescan Server