TrendMicro Officescan Widget Remote Command Execution Exploit

TrendMicro is prone to an abuse in the talker.php function to get authentication bypass, combined with the mod TMCSS user-supplied unvalidated input before using it to execute a system calls leads us to execute arbitrary code. This exploit installs an OS Agent.
Exploit Platform
Product Name