Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2018-6230

Description

A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 search configuration script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.

POC

Reference

- https://www.coresecurity.com/advisories/trend-micro-email-encryption-gateway-multiple-vulnerabilities

- https://www.exploit-db.com/exploits/44166/

Github

- https://github.com/ARPSyndicate/cvemon