PT-2015-7545 · Manageengine · Zoho Manageengine Eventlog Analyzer

Xistence

·

Publicado

2015-09-28

·

Atualizado

2020-03-26

·

CVE-2015-7387

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ManageEngine EventLog Analyzer versions 10.6 build 10060 and earlier
Description The issue allows remote attackers to bypass intended restrictions and execute arbitrary SQL commands. This can be achieved by sending an allowed query followed by a disallowed one in the query parameter to the "event/runQuery.do" endpoint, as demonstrated by "SELECT 1;INSERT INTO."
Recommendations For ManageEngine EventLog Analyzer versions 10.6 build 10060 and earlier, update to Build 11200 or later to resolve the issue.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-7387

Produtos afetados

Zoho Manageengine Eventlog Analyzer