PT-2008-2107 · Zoho · Zoho Manageengine Applications Manager
Publicado
2008-01-29
·
Atualizado
2017-08-08
·
CVE-2008-0475
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ManageEngine Applications Manager version 8.1 build 8100
Description
The issue allows remote attackers to obtain sensitive information via an invalid URI. For example, using the "/-" URI, an attacker can access sensitive data, such as that found in the "Home->Summary" section.
Recommendations
For ManageEngine Applications Manager version 8.1 build 8100, consider restricting access to the sensitive information section, such as "Home->Summary", until a fix is available. As a temporary workaround, avoid using invalid URIs, such as "/-", to prevent potential exploitation.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Zoho Manageengine Applications Manager