ManageEngine Applications Manage 13.5 Remote Code Execution
Posted by deepcore on March 15, 2018 – 12:44 am
This Metasploit module exploits command injection vulnerability in the ManageEngine Application Manager product. An unauthenticated user can execute a operating system command under the context of privileged user. Publicly accessible testCredential.do endpoint takes multiple user inputs and validates supplied credentials by accessing given system. This endpoint calls a several internal classes and then executes powershell script without validating user supplied parameter when the given system is OfficeSharePointServer.
Post a reply
You must be logged in to post a comment.