CVE-2016-9488
ManageEngine Applications Manager versions 12 and 13 suffer from remote SQL injection vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /servlet/MenuHandlerServlet, which is vulnerable to SQL injection. The attacker could extract users' password hashes, which are MD5 hashes without salt, and, depending on the database type and its configuration, could also execute operating system commands using SQL queries.
ManageEngine Applications Manager en versiones 12 y 13 anteriores al build 13200 sufre de vulnerabilidades de inyección SQL remota. Un atacante no autenticado puede acceder a la URL /servlet/MenuHandlerServlet, que es vulnerable a la inyección SQL. El atacante puede extraer los hashes de las contraseñas de los usuarios, que son hashes MD5 sin sal y, dependiendo del tipo de base de datos y su configuración, podría también ejecutar comandos del sistema operativo usando consultas SQL.
ManageEngine Applications Manager version 13 suffers from a remote SQL injection vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-11-21 CVE Reserved
- 2017-04-04 CVE Published
- 2020-07-26 First Exploit
- 2024-02-19 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/158554/ManageEngine-Applications-Manager-13-SQL-Injection.html | X_refsource_misc | |
http://seclists.org/fulldisclosure/2017/Apr/9 | Mailing List | |
http://www.securityfocus.com/bid/97394 | Third Party Advisory | |
https://packetstormsecurity.com/files/142022/ManageEngine-Applications-Manager-12-13-XSS-SQL-Injection-Code-Execution.html | Third Party Advisory | |
https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2016-9488.html | X_refsource_confirm |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/48692 | 2020-07-26 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Manageengine Search vendor "Manageengine" | Applications Manager Search vendor "Manageengine" for product "Applications Manager" | 12.0 Search vendor "Manageengine" for product "Applications Manager" and version "12.0" | - |
Affected
| ||||||
Manageengine Search vendor "Manageengine" | Applications Manager Search vendor "Manageengine" for product "Applications Manager" | 13.0 Search vendor "Manageengine" for product "Applications Manager" and version "13.0" | - |
Affected
|