← Vulnerability feed

Vulnerability record · CVE-2016-8593 · published 28 April 2017

CVE-2016-8593: Trendmicro threat discovery appliance path traversal vulnerability

Trendmicro · Threat Discovery Appliance

Directory traversal vulnerability in upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via a .. (dot dot) in the dID parameter.

8.8 CVSS 3.0 High EPSS 7.0% · top 6.0% CWE-22 · Path traversal
8.8CVSS 3.0 base score, v2 6.5
7.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via a .. (dot dot) in the dID parameter.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-8593 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-8584Trendmicro threat discovery appliance improper access control vulnerabilityTrend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which allows remote attackers to bypass authentication…EPSS 5.6%9.8CVE-2016-7547Trend Micro Threat Discovery Appliance timezone parameter command executionThe admin_sys_time.cgi interface in Trend Micro Threat Discovery Appliance 2.6.1062r1 fails to properly handle the timezone parameter, allowing comma…EPSS 93%analysed9.8CVE-2016-7552Trend Micro Threat Discovery Appliance path traversal in session_id cookieThe Trend Micro Threat Discovery Appliance 2.6.1062r1 processes the session_id cookie without sanitizing path traversal sequences, allowing a remote,…EPSS 93%analysed8.8CVE-2016-8585Trendmicro threat discovery appliance permissions and access controls vulnerabilityadmin_sys_time.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as th…EPSS 7.2%8.8CVE-2016-8586Trendmicro threat discovery appliance permissions and access controls vulnerabilitydetected_potential_files.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary …EPSS 6.1%8.8CVE-2016-8589Trendmicro threat discovery appliance permissions and access controls vulnerabilitylog_query_dae.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the…EPSS 5.7%8.8CVE-2016-8590Trendmicro threat discovery appliance permissions and access controls vulnerabilitylog_query_dlp.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the…EPSS 5.7%8.8CVE-2016-8591Trendmicro threat discovery appliance permissions and access controls vulnerabilitylog_query.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the roo…EPSS 6.2%

Source: NIST National Vulnerability Database (record CVE-2016-8593), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.