vendor:
Exchange Reporter Plus
by:
Kacper Szurek
7.5
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Exchange Reporter Plus
Affected Version From: <= 5310
Affected Version To: 5310
Patch Exists: YES
Related CWE: N/A
CPE: a:manageengine:exchange_reporter_plus
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
ManageEngine Exchange Reporter Plus <= 5310 Unauthenticated RCE
Java servlet `ADSHACluster` executes `bcp.exe` file which can be passed using `BCP_EXE` param.
Mitigation:
Update to version 5311