EIP-2026-102495
PRE-CVEManageEngine DeviceExpert 5.6 Java Server ScheduleResultViewer servlet - Directory Traversal
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102495. PoCs published by rgod.
AI-analyzed exploit summary This exploit leverages an unauthenticated directory traversal vulnerability in ManageEngine DeviceExpert 5.6's ScheduleResultViewer servlet to disclose arbitrary files, including authentication credentials and database backups. The PoC demonstrates file retrieval via crafted HTTP requests to the servlet.
Description
ManageEngine DeviceExpert 5.6 Java Server ScheduleResultViewer servlet - Directory Traversal
Exploits (1)
This exploit leverages an unauthenticated directory traversal vulnerability in ManageEngine DeviceExpert 5.6's ScheduleResultViewer servlet to disclose arbitrary files, including authentication credentials and database backups. The PoC demonstrates file retrieval via crafted HTTP requests to the servlet.