Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote authenticated users to obtain access to the database via a direct request to event/runQuery.do. Fixed in Build 10000.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ZOHO ManageEngine EventLog Analyzer 权限许可和访问控制问题漏洞
Vulnerability Description
ZOHO ManageEngine EventLog Analyzer是美国卓豪(ZOHO)公司的一套系统、事件日志分析软件。该软件能够对全网范围内的主机、服务器、网络设备以及各种应用服务系统等产生的日志,进行全面收集和细致分析。 ZOHO ManageEngine EventLog Analyzer 9.0 build 9002版本和8.2 build 8020版本中存在权限许可和访问控制问题漏洞,该漏洞源于程序没有正确限制对数据库浏览器的访问。远程攻击者可通过向event/runQuery.do页面发
CVSS Information
N/A
Vulnerability Type
N/A