Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Elvin Hayes Gentiles

Pesquisador deTrustwave SpiderLabs
#31651de 53,639
8.1CVSS total
Vulnerabilidades · 1
PT-2019-7900
8.1
2019-05-23
Zoho · Zoho Manageengine Applications Manager · CVE-2017-11738
**Name of the Vulnerable Software and Affected Versions** Zoho ManageEngine Application Manager versions prior to 14.6 Build 14660 **Description** The issue concerns a Time-based Blind SQL Injection attack. Specifically, the `haid` parameter of the "/auditLogAction.do" module is vulnerable. **Recommendations** For versions prior to 14.6 Build 14660, update to version 14.6 Build 14660 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/auditLogAction.do" module to minimize the risk of exploitation. Avoid using the `haid` parameter in the affected module until the issue is resolved.