EIP-2026-103979
PRE-CVEManageEngine Security Manager Plus 5.5 build 5505 - SQL Injection (Metasploit)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103979. PoCs published by Metasploit.
AI-analyzed exploit summary This Metasploit module exploits a SQL injection vulnerability in ManageEngine Security Manager Plus 5.5 build 5505, allowing unauthenticated remote code execution via crafted SQL queries in the advanced search page. The exploit generates a malicious JSP payload, writes it to the target filesystem via SQLi, and triggers execution to achieve SYSTEM-level access on Windows or root-level on Linux.
Description
ManageEngine Security Manager Plus 5.5 build 5505 - SQL Injection (Metasploit)
Exploits (1)
This Metasploit module exploits a SQL injection vulnerability in ManageEngine Security Manager Plus 5.5 build 5505, allowing unauthenticated remote code execution via crafted SQL queries in the advanced search page. The exploit generates a malicious JSP payload, writes it to the target filesystem via SQLi, and triggers execution to achieve SYSTEM-level access on Windows or root-level on Linux.