vendor:
ManageEngine Network Configuration Manager
by:
Kaustubh G. Padwad
9,8
CVSS
CRITICAL
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: ManageEngine Network Configuration Manager
Affected Version From: Network Configuration Manager Build 11000
Affected Version To: Network Configuration Manager Build 11000
Patch Exists: Yes
Related CWE: CVE-2016-7000
CPE: a:zoho:manageengine_network_configuration_manager:11000
Metasploit:
https://www.rapid7.com/db/vulnerabilities/acrobat-cve-2016-7013/, https://www.rapid7.com/db/vulnerabilities/acrobat-cve-2016-6943/, https://www.rapid7.com/db/vulnerabilities/acrobat-cve-2016-6947/, https://www.rapid7.com/db/vulnerabilities/acrobat-cve-2016-6954/, https://www.rapid7.com/db/vulnerabilities/acrobat-cve-2016-6960/, https://www.rapid7.com/db/vulnerabilities/acrobat-cve-2016-6970/, https://www.rapid7.com/db/vulnerabilities/acrobat-cve-2016-6973/, https://www.rapid7.com/db/vulnerabilities/acrobat-cve-2016-6975/, https://www.rapid7.com/db/vulnerabilities/acrobat-cve-2016-6995/, https://www.rapid7.com/db/vulnerabilities/acrobat-cve-2016-7003/, https://www.rapid7.com/db/vulnerabilities/acrobat-cve-2016-7007/, https://www.rapid7.com/db/vulnerabilities/acrobat-cve-2016-7008/, https://www.rapid7.com/db/vulnerabilities/acrobat-cve-2016-7015/, https://www.rapid7.com/db/vulnerabilities/acrobat-cve-2016-7017/, https://www.rapid7.com/db/vulnerabilities/acrobat-cve-2016-7853/, https://www.rapid7.com/db/vulnerabilities/acrobat-cve-2016-6976/, https://www.rapid7.com/db/vulnerabilities/acrobat-cve-2016-7012/, https://www.rapid7.com/db/vulnerabilities/acrobat-cve-2016-6940/, https://www.rapid7.com/db/vulnerabilities/acrobat-cve-2016-6941/, https://www.rapid7.com/db/vulnerabilities/acrobat-cve-2016-6996/, https://www.rapid7.com/db/?q=CVE-2016-7000&type=&page=2, https://www.rapid7.com/db/?q=CVE-2016-7000&type=&page=3, https://www.rapid7.com/db/?q=CVE-2016-7000&type=&page=2
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2016
Cross-Site Request Forgery (CSRF) Vulnerability in ManageEngine Network Configuration Management
This Cross-Site Request Forgery vulnerability enables an anonymous attacker to add an device into the application. and device fileds are vulnerable tocross site scripting attack This leads to compromising the whole domain as the application.
Mitigation:
The vendor has released a patch to address this vulnerability.