module
ManageEngine Security Manager Plus 5.5 Build 5505 SQL Injection
Disclosed | Created |
---|---|
2012-10-18 | 2018-05-30 |
Disclosed
2012-10-18
Created
2018-05-30
Description
This module exploits a SQL injection found in ManageEngine Security Manager Plus
advanced search page, which results in remote code execution under the context of
SYSTEM in Windows; or as the user in Linux. Authentication is not required in order
to exploit this vulnerability.
advanced search page, which results in remote code execution under the context of
SYSTEM in Windows; or as the user in Linux. Authentication is not required in order
to exploit this vulnerability.
Authors
xistence xistence@0x90.nl
sinn3r sinn3r@metasploit.com
egypt egypt@metasploit.com
sinn3r sinn3r@metasploit.com
egypt egypt@metasploit.com
Platform
Linux,Windows
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.