CVE-2017-11740
23.05.2019, 16:29
In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon the occurrence of an alarm. An attacker can abuse this functionality by uploading a malicious script that can be executed on the remote system.Enginsight
Vendor | Product | Version |
---|---|---|
zohocorp | manageengine_applications_manager | 13.1:13100 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration