PT-2015-7545 · Manageengine · Zoho Manageengine Eventlog Analyzer

Xistence

·

Published

2015-09-28

·

Updated

2020-03-26

·

CVE-2015-7387

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ManageEngine EventLog Analyzer versions 10.6 build 10060 and earlier
Description The issue allows remote attackers to bypass intended restrictions and execute arbitrary SQL commands. This can be achieved by sending an allowed query followed by a disallowed one in the query parameter to the "event/runQuery.do" endpoint, as demonstrated by "SELECT 1;INSERT INTO."
Recommendations For ManageEngine EventLog Analyzer versions 10.6 build 10060 and earlier, update to Build 11200 or later to resolve the issue.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-7387

Affected Products

Zoho Manageengine Eventlog Analyzer