漏洞描述 【漏洞对象】ManageEngine Applications Manager 【涉及版本】ManageEngine Applications Manager【漏洞描述】 ManageEngine ApplicationsManager应用性能监控管理系统/GraphicalView.do文件sql注入,可造成数据泄露,甚至服务器被入侵。
相关漏洞推荐 ETAP Safety Manager 跨站脚本漏洞 (CVE-2023-53878)Member Login Script 3.3客户端去同步漏洞 POC CVE-2020-26836: SAP Solution Manager - Open Redirect POC CVE-2021-37415: Zoho ManageEngine ServiceDesk Plus - Authentication Bypass POC CVE-2023-23897: Ozette Plugins - Cross-Site Request Forgery POC bitrix-log-file-disclosure: Bitrix Site Manager - Log File Disclosure POC nexus-repository-anonymous-access: Nexus Repository Manager - Anonymous Access Enabled POC wp-woocommerce-admin-fpd: WordPress Plugin WooCommerce Admin (woocommerce-admin) Full Path Disclosure POC CVE-2017-5983: JIRA Workflow Designer Plugin in Atlassian JIRA Server > 6.3.0 - Remote Code Execution (XXE) POC CVE-2019-25213: WordPress Advanced Access Manager - Path Traversal POC CVE-2021-4449: ZoomSounds Plugin - Unauthenticated Arbitrary File Upload POC CVE-2023-38875: PHP Login System 2.0.1 - Cross-Site Scripting POC CVE-2023-5815: News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Local File Inclusion