Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-3272. PoCs published by Core Security.
AI-analyzed exploit summary This exploit demonstrates a security bypass vulnerability in ManageEngine ADSelfService Plus by sending a crafted POST request to bypass authentication. The request includes manipulated parameters to validate user answers without proper authorization.
Description
accounts/ValidateAnswers in the security-questions implementation in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 makes it easier for remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, via a modified (1) Hide_Captcha or (2) quesList parameter in a validateAll action.
Exploits (1)
This exploit demonstrates a security bypass vulnerability in ManageEngine ADSelfService Plus by sending a crafted POST request to bypass authentication. The request includes manipulated parameters to validate user answers without proper authorization.