EIP-2026-118759
PRE-CVEManageEngine Security Manager Plus 5.5 build 5505 - Remote SYSTEM SQL Injection (Metasploit)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-118759. PoCs published by xistence.
AI-analyzed exploit summary This Metasploit module exploits a SQL injection vulnerability in ManageEngine Security Manager Plus to achieve remote code execution by uploading a malicious JSP file and executing it. The exploit leverages a union-based SQL injection to write a JSP payload to the web root, which then downloads and executes a malicious executable.
Description
ManageEngine Security Manager Plus 5.5 build 5505 - Remote SYSTEM SQL Injection (Metasploit)
Exploits (1)
This Metasploit module exploits a SQL injection vulnerability in ManageEngine Security Manager Plus to achieve remote code execution by uploading a malicious JSP file and executing it. The exploit leverages a union-based SQL injection to write a JSP payload to the web root, which then downloads and executes a malicious executable.