PoC Index

CVE-2018-6228

HIGH 10.0EPSS 10.2%

A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.

CVSS v3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
10.25% chance of exploitation in the next 30 days, 95th percentile
Published
2018-03-15
Updated
2024-08-05

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related