Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.802483
Kategorie:Web application abuses
Titel:Zoho ManageEngine Security Manager Plus Multiple Vulnerabilities
Zusammenfassung:This host is running Zoho ManageEngine Security Manager Plus; and is prone to multiple vulnerabilities.
Beschreibung:Summary:
This host is running Zoho ManageEngine Security Manager Plus
and is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws are due to:

- An input passed to the 'f' parameter via 'store' script is not properly
sanitised before being used. This allows to download the complete database
and thus gather logins which lead to uploading web site files which could
be used for malicious actions

- The SQL injection is possible on the 'Advanced Search', the input is not
validated correctly.

Vulnerability Impact:
Successful exploitation will allow remote attackers to perform
directory traversal attacks, read/download the arbitrary files and to manipulate
SQL queries by injecting arbitrary SQL code.

Affected Software/OS:
ManageEngine Security Manager Plus version 5.5 build 5505
and prior

Solution:
Apply the patch from the referenced link or update to latest version.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

CopyrightCopyright (C) 2012 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.