Back to search
CVE-2015-7766
Published: Oct 9, 2015
Modified: Sep 17, 2024
PUBLISHED
Description
PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions via a comment in the query to api/json/admin/SubmitQuery, as demonstrated by "INSERT/**/INTO."
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20150915 ManageEngine OpManager multiple vulnerabilities
mailing-list
x_refsource_FULLDISC
38221
exploit
x_refsource_EXPLOIT-DB
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now