Multiple SQL Injection vulnerabilities are detected in Manage Engines Application Manager v10 b10500.
The vulnerability allows an attacker (remote) or local low privileged user account to inject/execute own sql commands
on the affected application dbms without user inter action. The vulnerabilities are located in the mypage.do or rca.jsp
module(s) and the bound vulnerable parameters selectedpageid & resourceid. Successful exploitation of the vulnerability
results in dbms & application compromise.
Multiple non persistent cross site scripting vulnerabilities are detected in Manage Engines Application Manager v10 b10500.
The vulnerability allows remote attackers to hijack website customer, moderator or admin sessions with medium or high
required user inter action or local low privileged user account. The vulnerabilities are located in the showCustom.do, MyPage.do,
ThresholdActionConfiguration.jsp, showresource.do or ProcessTemplates.do files with the bound vulnreable parameters redirectto, &type,
attributeToSelect, templatetype, forpage & monitorname. Successful exploitation can result in account steal, phishing & client-side
content request manipulation.
The blind sql injection vulnerabilities can be exploited by remote attackers without user inter action or privileged user account.
For demonstration or reproduce ...
The non persistent cross site scripting vulnerabilities can be exploited by remote attackers with medium or high required user inter action.
For demonstration or reproduce ...