Record summary

CVE-2016-9488 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.

Description

ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /servlet/MenuHandlerServlet, which is vulnerable to SQL injection. The attacker could extract users' password hashes, which are MD5 hashes without salt, and, depending on the database type and its configuration, could also execute operating system commands using SQL queries.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List12affected
13affected

Proofs of concept

1

Catalogued exploits

ExploitDBManageEngine Applications Manager 13 - 'MenuHandlerServlet' SQL InjectionExploitDB exploitby aldormNot analyzed1 file
ExploitDB

PoC details

References

6