EIP-2026-103978
PRE-CVEManageEngine Security Manager Plus 5.5 build 5505 - Remote Root/SYSTEM SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103978. PoCs published by xistence.
AI-analyzed exploit summary This exploit leverages an unauthenticated SQL injection vulnerability in ManageEngine Security Manager Plus to write a JSP shell to the server, enabling remote code execution with SYSTEM/root privileges. The payload crafts a malicious SQL query to write a reverse shell JSP file, which is then accessed to trigger the shell.
Description
ManageEngine Security Manager Plus 5.5 build 5505 - Remote Root/SYSTEM SQL Injection
Exploits (1)
This exploit leverages an unauthenticated SQL injection vulnerability in ManageEngine Security Manager Plus to write a JSP shell to the server, enabling remote code execution with SYSTEM/root privileges. The payload crafts a malicious SQL query to write a reverse shell JSP file, which is then accessed to trigger the shell.