CVE-2017-17552
07.02.2018, 17:29
/LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicious URL as trusted.
| Vendor | Product | Version |
|---|---|---|
| zohocorp | manageengine_admanager_plus | 𝑥 < 6.6 |
| zohocorp | manageengine_admanager_plus | 6.6:6601 |
| zohocorp | manageengine_admanager_plus | 6.6:6602 |
| zohocorp | manageengine_admanager_plus | 6.6:6610 |
| zohocorp | manageengine_admanager_plus | 6.6:6611 |
| zohocorp | manageengine_admanager_plus | 6.6:6612 |
| zohocorp | manageengine_admanager_plus | 6.6:6613 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration