Manageengine admanager plus 6.5.7 html injection Vulnerability / Exploit
/
/
/
Exploits / Vulnerability Discovered : 2018-08-25 |
Type : webapps |
Platform : windows
This exploit / vulnerability Manageengine admanager plus 6.5.7 html injection is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
# Exploit Title: ManageEngine ADManager Plus 6.5.7 - HTML Injection
# Date: 2018-08-21
# Exploit Author: Ismail Tasdelen
# Vendor Homepage: https://www.manageengine.com/
# Hardware Link : https://www.manageengine.com/products/ad-manager/
# Software : ZOHO Corp ManageEngine ADManager Plus
# Product Version: 6.5.7
# Vulernability Type : Code Injection
# Vulenrability : HTML Injection
# CVE : CVE-2018-15608
# ZOHO Corp ManageEngine ADManager Plus 6.5.7 allows HTML Injection on
# the "AD Delegation" "Help Desk Technicians" screen.