VYPR
High severity7.3NVD Advisory· Published Apr 28, 2017· Updated Jun 17, 2026

CVE-2016-8588

CVE-2016-8588

Description

The hotfix_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the file name of an uploaded file.

Affected products

2
  • cpe:2.3:a:trendmicro:threat_discovery_appliance:*:r1:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:trendmicro:threat_discovery_appliance:*:r1:*:*:*:*:*:*range: <=2.6.1062
    • (no CPE)range: <=2.6.1062r1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.