9.8
CVSSv3

CVE-2017-11346

Published: 17/07/2017 Updated: 12/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Zoho ManageEngine Desktop Central before build 100092 allows remote malicious users to execute arbitrary code via vectors involving the upload of help desk videos.

Vulnerable Product Search on Vulmon Subscribe to Product

zohocorp manageengine desktop central

Exploits

# Exploit Title: ManageEngine Desktop Central 10 Build 100087 RCE # Date: 24-07-2017 # Software Link: wwwmanageenginecom/products/desktop-central/ # Exploit Author: Kacper Szurek # Contact: twittercom/KacperSzurek # Website: securityszurekpl/ # CVE: CVE-2017-11346 # Category: remote 1 Description When uploading a ...
This Metasploit module exploits a vulnerability found in ManageEngine Desktop Central 10 When uploading a file, the FileUploadServlet class does not check the user-controlled fileName parameter This allows a remote attacker to create a malicious file and place it under a directory that allows server-side scripts to run, which results in remote co ...