High severity8.8NVD Advisory· Published May 25, 2018· Updated Jun 17, 2026
CVE-2018-10350
CVE-2018-10350
Description
A SQL injection remote code execution vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw within the handling of parameters provided to wcs\_bwlists\_handler.php. Authentication is required in order to exploit this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
23.x+ 1 more
- (no CPE)range: 3.x
- (no CPE)range: 3.0, 3.1, 3.2, 3.3
Patches
Vulnerability mechanics
References
2- success.trendmicro.com/solution/1119715nvdVendor Advisory
- www.zerodayinitiative.com/advisories/ZDI-18-421/nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.