ManageEngine ADAudit Plus Path Traversal / XML Injection

Discussion in 'News Aggregator' started by Packet Storm, 9 Aug 2022.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits CVE-2022-28219, which is a pair of vulnerabilities in ManageEngine ADAudit Plus versions before build 7060. They include a path traversal in the /cewolf endpoint along with a blind XML external entity injection vulnerability to upload and execute a file.

    Continue reading...
     

Share This Page

Loading...