CVE-2018-6228
critical · 9.8A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.
9.8
CVSS
10.2%
EPSS (exploit prob.)
95th
EPSS percentile
2018-03-15
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-89
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| trendmicro | email_encryption_gateway | 5.5 |
Check a specific version with /api/v1/cve/match.
References
- https://success.trendmicro.com/solution/1119349
- https://www.coresecurity.com/advisories/trend-micro-email-encryption-gateway-multiple-vulnerabilities
- https://www.exploit-db.com/exploits/44166/
- https://success.trendmicro.com/solution/1119349
- https://www.coresecurity.com/advisories/trend-micro-email-encryption-gateway-multiple-vulnerabilities
- https://www.exploit-db.com/exploits/44166/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-6228