RSS   Vulnerabilities for
'Interscan messaging security suite'
   RSS

2012-09-17
 
CVE-2012-2996

CWE-352
 

 
Cross-site request forgery (CSRF) vulnerability in saveAccountSubTab.imss in Trend Micro InterScan Messaging Security Suite 7.1-Build_Win32_1394 allows remote attackers to hijack the authentication of administrators for requests that create admin accounts via a saveAuth action.

 
 
CVE-2012-2995

CWE-79
 

 
Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro InterScan Messaging Security Suite 7.1-Build_Win32_1394 allow remote attackers to inject arbitrary web script or HTML via (1) the wrsApprovedURL parameter to addRuleAttrWrsApproveUrl.imss or (2) the src parameter to initUpdSchPage.imss.

 
2006-03-24
 
CVE-2006-1380

 

 
ISNTSmtp directory in Trend Micro InterScan Messaging Security Suite (IMSS) 5.5 build 1183 and possibly other versions before 5.7.0.1121, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying ISNTSysMonitor.exe.

 

 >>> Vendor: Trendmicro 34 Products
Internet security
Officescan
Trend micro internet security
Housecall
Trend micro antivirus
Internet security 2010
Interscan messaging security suite
Interscan messaging security virtual appliance
Interscan web security virtual appliance
Tmeext.sys
Maximum security
Premium security
Antivirus+
Mobile security
Threat discovery appliance
Serverprotect
Deep discovery director
Control manager
Deep discovery email inspector
Trend micro control manager
Smart protection server
Web security virtual appliance
Officescan xg
Scanmail
Encryption for email
Email encryption gateway
Endpoint application control
Antivirus + security
Officescan monthly
Interscan web security suite
Deep discovery inspector
Dr. safety
Apex one
Business security


Copyright 2019, cxsecurity.com

 

Back to Top