CVE-2016-5840: Trend Micro Deep Discovery Inspector
High severity, CVSS 7.2. EPSS: 7.8% chance of exploitation in the next 30 days.
hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to execute arbitrary code via shell metacharacters in the filename parameter of the Content-Disposition header.
Affected products
- Trend Micro Deep Discovery Inspector: version 3.7 only; version 3.81 only; version 3.82 only
Published 2016-06-30. Last modified 2026-06-17.