Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmview request.
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Manageengine_applications_manager | Zohocorp | 14.0 (including) | 14.0 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14000 (including) | 14.0-build14000 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14010 (including) | 14.0-build14010 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14020 (including) | 14.0-build14020 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14030 (including) | 14.0-build14030 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14040 (including) | 14.0-build14040 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14050 (including) | 14.0-build14050 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14060 (including) | 14.0-build14060 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14070 (including) | 14.0-build14070 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14071 (including) | 14.0-build14071 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14072 (including) | 14.0-build14072 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14073 (including) | 14.0-build14073 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14080 (including) | 14.0-build14080 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14090 (including) | 14.0-build14090 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14100 (including) | 14.0-build14100 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14110 (including) | 14.0-build14110 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14120 (including) | 14.0-build14120 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14130 (including) | 14.0-build14130 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14140 (including) | 14.0-build14140 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14150 (including) | 14.0-build14150 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14160 (including) | 14.0-build14160 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14170 (including) | 14.0-build14170 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14180 (including) | 14.0-build14180 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14190 (including) | 14.0-build14190 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14200 (including) | 14.0-build14200 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14210 (including) | 14.0-build14210 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14220 (including) | 14.0-build14220 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14230 (including) | 14.0-build14230 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14240 (including) | 14.0-build14240 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14250 (including) | 14.0-build14250 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14260 (including) | 14.0-build14260 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14261 (including) | 14.0-build14261 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14262 (including) | 14.0-build14262 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14270 (including) | 14.0-build14270 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14280 (including) | 14.0-build14280 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14290 (including) | 14.0-build14290 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14300 (including) | 14.0-build14300 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14310 (including) | 14.0-build14310 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14330 (including) | 14.0-build14330 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14331 (including) | 14.0-build14331 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14332 (including) | 14.0-build14332 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14340 (including) | 14.0-build14340 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14350 (including) | 14.0-build14350 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14360 (including) | 14.0-build14360 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14361 (including) | 14.0-build14361 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14370 (including) | 14.0-build14370 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14380 (including) | 14.0-build14380 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14390 (including) | 14.0-build14390 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14400 (including) | 14.0-build14400 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14401 (including) | 14.0-build14401 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14410 (including) | 14.0-build14410 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14420 (including) | 14.0-build14420 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14430 (including) | 14.0-build14430 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14440 (including) | 14.0-build14440 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14450 (including) | 14.0-build14450 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14460 (including) | 14.0-build14460 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14470 (including) | 14.0-build14470 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14480 (including) | 14.0-build14480 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14490 (including) | 14.0-build14490 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14500 (including) | 14.0-build14500 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14510 (including) | 14.0-build14510 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14520 (including) | 14.0-build14520 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14530 (including) | 14.0-build14530 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14531 (including) | 14.0-build14531 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14532 (including) | 14.0-build14532 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14533 (including) | 14.0-build14533 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14540 (including) | 14.0-build14540 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14550 (including) | 14.0-build14550 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14560 (including) | 14.0-build14560 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14570 (including) | 14.0-build14570 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14580 (including) | 14.0-build14580 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14590 (including) | 14.0-build14590 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14600 (including) | 14.0-build14600 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14610 (including) | 14.0-build14610 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14620 (including) | 14.0-build14620 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14630 (including) | 14.0-build14630 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14660 (including) | 14.0-build14660 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14670 (including) | 14.0-build14670 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14681 (including) | 14.0-build14681 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14682 (including) | 14.0-build14682 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14683 (including) | 14.0-build14683 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14684 (including) | 14.0-build14684 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14685 (including) | 14.0-build14685 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14690 (including) | 14.0-build14690 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14700 (including) | 14.0-build14700 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14710 (including) | 14.0-build14710 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14720 (including) | 14.0-build14720 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14730 (including) | 14.0-build14730 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14740 (including) | 14.0-build14740 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14750 (including) | 14.0-build14750 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14760 (including) | 14.0-build14760 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14770 (including) | 14.0-build14770 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14780 (including) | 14.0-build14780 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14781 (including) | 14.0-build14781 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14790 (including) | 14.0-build14790 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14800 (including) | 14.0-build14800 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14811 (including) | 14.0-build14811 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14820 (including) | 14.0-build14820 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14830 (including) | 14.0-build14830 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14840 (including) | 14.0-build14840 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14841 (including) | 14.0-build14841 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14842 (including) | 14.0-build14842 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14843 (including) | 14.0-build14843 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14850 (including) | 14.0-build14850 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14860 (including) | 14.0-build14860 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14870 (including) | 14.0-build14870 (including) |
Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data. This can be used to alter query logic to bypass security checks, or to insert additional statements that modify the back-end database, possibly including execution of system commands. SQL injection has become a common issue with database-driven web sites. The flaw is easily detected, and easily exploited, and as such, any site or product package with even a minimal user base is likely to be subject to an attempted attack of this kind. This flaw depends on the fact that SQL makes no real distinction between the control and data planes.