Описание
In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-based Blind SQL Injection attack.
Ссылки
- Not Applicable
- Vendor Advisory
- ExploitThird Party Advisory
- Not Applicable
- Vendor Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:zohocorp:manageengine_applications_manager:13.1:13100:*:*:*:*:*:*
EPSS
Процентиль: 74%
0.00835
Низкий
8.1 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-89
Связанные уязвимости
github
больше 3 лет назад
In Zoho ManageEngine Application Manager 13.1 Build 13100, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-based Blind SQL Injection attack.
EPSS
Процентиль: 74%
0.00835
Низкий
8.1 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-89