SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when RestfulServiceUtility.NET.dll doesn't properly validate user provided strings before constructing SQL queries. Formerly ZDI-CAN-4639 and ZDI-CAN-4638.Referenceshttp://www.securityfocus.com/bid/100078http://www.zerodayinitiative.com/advisories/ZDI-17-499http://www.securitytracker.com/id/1039049https://success.trendmicro.com/solution/1117722http://www.zerodayinitiative.com/advisories/ZDI-17-498