{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-21T12:46:34.938","vulnerabilities":[{"cve":{"id":"CVE-2018-10350","sourceIdentifier":"security@trendmicro.com","published":"2018-05-25T15:29:00.257","lastModified":"2026-06-17T01:33:52.900","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A SQL injection remote code execution vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw within the handling of parameters provided to wcs\\_bwlists\\_handler.php.  Authentication is required in order to exploit this vulnerability."},{"lang":"es","value":"Una vulnerabilidad de ejecución remota de código por inyección SQL en Trend Micro Smart Protection Server (Standalone) 3.x podría permitir que un atacante remoto ejecute código arbitrario en instalaciones vulnerables debido a un error en la gestión de parámetros proporcionados a wcs\\_bwlists\\_handler.php. Se requiere autenticación para explotar esta vulnerabilidad."}],"affected":[{"source":"security@trendmicro.com","affectedData":[{"vendor":"Trend Micro","product":"Trend Micro Smart Protection Server (Standalone)","versions":[{"version":"3.0, 3.1, 3.2, 3.3","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","baseScore":9.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.0,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:trendmicro:smart_protection_server:3.0:*:*:*:*:*:*:*","matchCriteriaId":"E74019C0-01AD-4C0F-9ADE-099D6D7C8013"},{"vulnerable":true,"criteria":"cpe:2.3:a:trendmicro:smart_protection_server:3.1:*:*:*:*:*:*:*","matchCriteriaId":"CB62FC55-4EA1-485E-9381-C14BA2F1E074"},{"vulnerable":true,"criteria":"cpe:2.3:a:trendmicro:smart_protection_server:3.2:*:*:*:*:*:*:*","matchCriteriaId":"4157366A-854E-4993-B08B-FAF7EA4D9ED2"},{"vulnerable":true,"criteria":"cpe:2.3:a:trendmicro:smart_protection_server:3.3:*:*:*:*:*:*:*","matchCriteriaId":"CD4082E4-88CC-4B48-AA49-B5EC28950D36"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*","matchCriteriaId":"703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"}]}]}],"references":[{"url":"https://success.trendmicro.com/solution/1119715","source":"security@trendmicro.com","tags":["Vendor Advisory"]},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-18-421/","source":"security@trendmicro.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://success.trendmicro.com/solution/1119715","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-18-421/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]}]}}]}