CVE-2017-11740

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
23/05/2019
Last modified:
23/05/2019

Description

In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon the occurrence of an alarm. An attacker can abuse this functionality by uploading a malicious script that can be executed on the remote system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zohocorp:manageengine_applications_manager:13.1:13100:*:*:*:*:*:*