Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-11448

Опубликовано: 22 апр. 2019
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Средний

Описание

An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. For example, the attacker can subsequently write arbitrary text to a .vbs file.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zohocorp:manageengine_applications_manager:*:*:*:*:*:*:*:*
Версия от 11.0 (включая) до 14.0 (включая)

EPSS

Процентиль: 95%
0.1739
Средний

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. For example, the attacker can subsequently write arbitrary text to a .vbs file.

EPSS

Процентиль: 95%
0.1739
Средний

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-89