vendor:
EventLog Analyzer
by:
Hans-Martin Muench
9
CVSS
CRITICAL
Unauthenticated remote code execution, Unauthenticated remote file disclosure, Unauthenticated remote SQL injection, Unauthenticated remote command injection
N/A
CWE
Product Name: EventLog Analyzer
Affected Version From: EventLog Analyzer 9.9 (Build 9002)
Affected Version To: EventLog Analyzer 9.9 (Build 9002)
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows/Linux
2014
ManageEngine EventLog Analyzer Multiple Vulnerabilities
ME EventLog Analyzer contains a 'agentUpload' servlet which is used by Agents to send log data to the server. This servlet is accessible without authentication and allows an attacker to upload arbitrary files to the server. This can be used to upload a malicious JSP file and execute arbitrary code on the server. The same servlet also allows an attacker to download arbitrary files from the server. It also contains a SQL injection vulnerability which allows an attacker to execute arbitrary SQL queries on the server. It also contains a command injection vulnerability which allows an attacker to execute arbitrary commands on the server.
Mitigation:
It is highly recommended not to use this software until a thorough security review has been performed by security professionals and all identified issues have been resolved.