PoC Index

CVE-2016-6267

HIGH 8.8EPSS 54.9%

SnmpUtils in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) spare_Community, (2) spare_AllowGroupIP, or (3) spare_AllowGroupNetmask parameter to admin_notification.php.

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
54.87% chance of exploitation in the next 30 days, 99th percentile
Published
2017-01-30
Updated
2024-08-06

Proof-of-concept exploits (1)

Metasploit modules (1)

References

Related