漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability
Vulnerability Description
ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of ManageEngine ADSelfService Plus. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Password Reset Portal used by the GINA client. The issue results from the lack of proper authentication of data received via HTTP. An attacker can leverage this vulnerability to bypass authentication and execute code in the context of SYSTEM. Was ZDI-CAN-17009.
CVSS Information
N/A
Vulnerability Type
对数据真实性的验证不充分
Vulnerability Title
ZOHO ManageEngine ADSelfService Plus 数据伪造问题漏洞
Vulnerability Description
ZOHO ManageEngine ADSelfService Plus是美国卓豪(ZOHO)公司的针对 Active Directory 和云应用程序的集成式自助密码管理和单点登录解决方案。 ZOHO ManageEngine ADSelfService Plus 存在数据伪造问题漏洞,该漏洞源于对通过 HTTP 接收的数据缺乏正确的身份验证, 攻击者可以利用此漏洞绕过身份验证并在 SYSTEM 上下文中执行代码。
CVSS Information
N/A
Vulnerability Type
N/A