Check Point Reference: | CPAI-2011-127 |
Date Published: | 5 Jan 2012 |
Severity: | Critical |
Last Updated: | Saturday 01 January, 2011 |
Source: | |
Protection Provided by: | |
Who is Vulnerable? | Trend Micro Control Manager 5.0 Trend Micro Control Manager 5.5 |
Vulnerability Description | A cross-site request forgery (XSRF) vulnerability has been reported in Trend Micro Control Manager. |
Vulnerability Details | The vulnerability is due to an error while handling CasLogDirectInsert.aspx requests. A remote attacker may exploit this vulnerability by enticing a user to open a specially crafted URI. Successful exploitation of this issue will allow the attacker to login to the administrator console and execute commands with the privileges of the affected service. |