Trend Micro Control Manager 'ApHost' Parameter Cross Site Scripting Vulnerability
14 Jul. 2012
Summary
Trend Micro Control Manager is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
Credit:
The original article can be found at: http://www.securityfocus.com/bid/48313
The information has been provided by Sow Ching Shiong through Secunia. .
Vulnerable Systems:
*Trend Micro Control Manager 5.5 Build 1250
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Trend Micro Control Manager 5.5 Build 1250 is vulnerable; other versions may also be affected.
Vendor Status:
Currently we are not aware of any vendor-supplied patches