SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when RestfulServiceUtility.NET.dll doesn't properly validate user provided strings before constructing SQL queries. Formerly ZDI-CAN-4639 and ZDI-CAN-4638.
| Software | From | Fixed in |
|---|---|---|
| trendmicro / control_manager | 6.0 | 6.0.x |