Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-7890

Опубликовано: 08 мар. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Высокий

Описание

A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The publicly accessible testCredential.do endpoint takes multiple user inputs and validates supplied credentials by accessing a specified system. This endpoint calls several internal classes, and then executes a PowerShell script. If the specified system is OfficeSharePointServer, then the username and password parameters to this script are not validated, leading to Command Injection.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zohocorp:manageengine_applications_manager:*:*:*:*:*:*:*:*
Версия до 13.6 (исключая)

EPSS

Процентиль: 99%
0.86279
Высокий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The publicly accessible testCredential.do endpoint takes multiple user inputs and validates supplied credentials by accessing a specified system. This endpoint calls several internal classes, and then executes a PowerShell script. If the specified system is OfficeSharePointServer, then the username and password parameters to this script are not validated, leading to Command Injection.

EPSS

Процентиль: 99%
0.86279
Высокий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-78