Multiple ManageEngine Products 'probeName' Parameter SQL Injection Vulnerability
BID:71509
Info
Multiple ManageEngine Products 'probeName' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 71509 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-7867 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 04 2014 12:00AM |
| Updated: | Dec 04 2014 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
ManageEngine Social IT Plus 11.0 ManageEngine OpManager 11.4 ManageEngine OpManager 11.3 ManageEngine IT360 10.4 ManageEngine IT360 10.3 |
| Not Vulnerable: | |
Discussion
Multiple ManageEngine Products 'probeName' Parameter SQL Injection Vulnerability
Multiple ManageEngine Products are prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
An attacker can exploit this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following products are affected:
ManageEngine Social IT 11.0
ManageEngine OpManager 11.3 and 11.4
ManageEngine IT360 10.3 and 10.4
Multiple ManageEngine Products are prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
An attacker can exploit this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following products are affected:
ManageEngine Social IT 11.0
ManageEngine OpManager 11.3 and 11.4
ManageEngine IT360 10.3 and 10.4
Exploit / POC
Multiple ManageEngine Products 'probeName' Parameter SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
References
Multiple ManageEngine Products 'probeName' Parameter SQL Injection Vulnerability
References:
References:
- Manage Engine Homepage (ManageEngine)
- SQL Injection Vulnerability FIx (ManageEngine)