Zoho ManageEngine Applications Manager CVE-2017-11740 Arbitrary File Upload Vulnerability
BID:108914
Info
Zoho ManageEngine Applications Manager CVE-2017-11740 Arbitrary File Upload Vulnerability
| Bugtraq ID: | 108914 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-11740 |
| Remote: | Yes |
| Local: | No |
| Published: | May 23 2019 12:00AM |
| Updated: | May 23 2019 12:00AM |
| Credit: | Elvin Hayes Gentiles of Trustwave SpiderLabs. |
| Vulnerable: |
Zoho ManageEngine Applications Manager 13.1 Build 13100 |
| Not Vulnerable: | |
Discussion
Zoho ManageEngine Applications Manager CVE-2017-11740 Arbitrary File Upload Vulnerability
Zoho ManageEngine Applications Manager is prone to an arbitrary-file-upload vulnerability.
An attacker can exploit this issue to upload arbitrary file, this can result in arbitrary code execution within the context of the vulnerable application.
Zoho ManageEngine Applications Manager version 13.1 build 13100 is vulnerable; other versions may also be affected.
Zoho ManageEngine Applications Manager is prone to an arbitrary-file-upload vulnerability.
An attacker can exploit this issue to upload arbitrary file, this can result in arbitrary code execution within the context of the vulnerable application.
Zoho ManageEngine Applications Manager version 13.1 build 13100 is vulnerable; other versions may also be affected.
Exploit / POC
Zoho ManageEngine Applications Manager CVE-2017-11740 Arbitrary File Upload Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.