Zoho ManageEngine Applications Manager '/auditLogAction.do' Module SQL Injection Vulnerability
BID:108470
CVE-2017-11738 |Info
Zoho ManageEngine Applications Manager '/auditLogAction.do' Module SQL Injection Vulnerability
| Bugtraq ID: | 108470 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-11738 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 09 2019 12:00AM |
| Updated: | Aug 09 2019 12:00AM |
| Credit: | Elvin Hayes Gentiles of Trustwave SpiderLabs |
| Vulnerable: |
Zoho ManageEngine Applications Manager 13.1 Build 13100 |
| Not Vulnerable: | |
Discussion
Zoho ManageEngine Applications Manager '/auditLogAction.do' Module SQL Injection Vulnerability
Zoho ManageEngine Applications Manager is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
An attacker may leverage this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
ManageEngine Applications Manager 13.1 Build 13100 is vulnerable; other versions may also be affected.
Zoho ManageEngine Applications Manager is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
An attacker may leverage this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
ManageEngine Applications Manager 13.1 Build 13100 is vulnerable; other versions may also be affected.
Exploit / POC
Zoho ManageEngine Applications Manager '/auditLogAction.do' Module SQL Injection Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
Zoho ManageEngine Applications Manager '/auditLogAction.do' Module SQL Injection Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Zoho ManageEngine Applications Manager '/auditLogAction.do' Module SQL Injection Vulnerability
References:
References: