Описание
In Zoho ManageEngine Application Manager 13.1 Build 13100, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-based Blind SQL Injection attack.
In Zoho ManageEngine Application Manager 13.1 Build 13100, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-based Blind SQL Injection attack.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2017-11738
- https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2017-11738.html
- https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=18734
- http://application.com
- http://manageengine.com
- http://www.securityfocus.com/bid/108470
EPSS
Процентиль: 74%
0.00835
Низкий
CVE ID
Связанные уязвимости
CVSS3: 8.1
nvd
больше 6 лет назад
In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-based Blind SQL Injection attack.
EPSS
Процентиль: 74%
0.00835
Низкий