E18-5n7n1
CVSS:
5.5 (AV:N/AC:L/Au:S/C:P/I:P/A:N)
False Positive:
t
Variants:
2
Year:
2018
Description
This strike exploits a blind SQL injection vulnerability in ManageEngine's OpManager application. The vulnerability is present in a API parameter for managing devices as a result of insufficient user input sanitization. Therefore, an attacker may be able to read arbitrary database records or even access system files, depending on the database's configuration.