ManageEngine Desktop Central 10...

- AV AC AU C I A
发布: 2017-07-24
修订: 2025-04-13

This Metasploit module exploits a vulnerability found in ManageEngine Desktop Central 10. When uploading a file, the FileUploadServlet class does not check the user-controlled fileName parameter. This allows a remote attacker to create a malicious file and place it under a directory that allows server-side scripts to run, which results in remote code execution under the context of SYSTEM. This exploit was successfully tested on version 10, build 100087.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息