Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

October 2nd, 2012, 10:01 GMT · By

BLOG

US-CERT Warns of SQL Injection Flaw in Trend Micro Control Manager

SHARE:

Adjust text size:


US-CERT warns of vulnerability in Trend Micro Control Manager Enlarge picture - US-CERT warns of vulnerability in Trend Micro Control Manager
The United States Computer Emergency Readiness Team (US-CERT) has issued an advisory to warn Trend Micro Control Manager customers of an SQL injection vulnerability that affects unpatched versions of the product.

The software doesn’t properly filter user-supplied input within the ad hoc query module. This allows a remote cybercriminal who has access to the Control Manager web interface to conduct an SQL injection attack in order to steal information, cause a denial of service state, or execute arbitrary code.

Trend Micro has been made aware of the issue. As a result, the security hole has been addressed in Trend Micro Control Manager version 5.5 and 6.0 with critical patches.

As a general good practice, US-CERT advises users to only allow connections from trusted networks and hosts because this way they could prevent an attacker from accessing the product’s web interface.

TELL US WHAT YOU THINK:

1,335 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Expert: USSD Codes Can Be Used to Remotely Reset Samsung Galaxy S3 Phones

Java Users Still Not Safe, Experts Report New Vulnerability to Oracle (Exclusive)

Security Explorations: Oracle Has Already Prepared the Fix for Java Zero-Day

One Billion Users Affected by Java Security Sandbox Bypass Vulnerability, Experts Say

Backdoor in phpMyAdmin Allows Hackers to Execute PHP Code

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM