SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  ManageEngine ADAudit Plus XXE Injection 2

Category: WEB-ATTACKS      

ManageEngine ADAudit Plus has vulnerable endpoints that allowed an unauthenticated attacker to exploit XML External Entities (XXE), Java deserialization and path traversal vulnerabilities. The chain could be leveraged to unauthenticated remote code execution.

References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1990


Relevant Information