PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions via a comment in the query to api/json/admin/SubmitQuery, as demonstrated by INSERT/**/INTO.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Manageengine_opmanager | Zohocorp | * | 11.5 (including) |
Manageengine_opmanager | Zohocorp | 11.6 (including) | 11.6 (including) |