{"id":"CVE-2016-7552","aliases":[],"url":"https://o3.security/vulnerability/CVE-2016-7552","summary":"On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files…","details":"On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can be used to bypass authentication or cause a DoS.","published":"2017-04-12T10:00:00.000Z","modified":"2024-08-06T02:04:55.596Z","cvss":null,"epss":{"score":0.93249,"percentile":0.99827,"asOf":"2026-08-25"},"cisaKev":null,"exploitsKnown":4,"affectedPackages":[],"fix":{"url":"https://github.com/rapid7/metasploit-framework/pull/8216/commits/0f07875a2ddb0bfbb4e985ab074e9fc56da1dcf6","label":"rapid7/metasploit-framework#8216"},"references":[{"type":"WEB","url":"https://github.com/rapid7/metasploit-framework/pull/8216/commits/0f07875a2ddb0bfbb4e985ab074e9fc56da1dcf6"},{"type":"WEB","url":"http://www.securityfocus.com/bid/97599"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2024-08-06T02:04:55.596Z"}}