ManageEngine OpManager Remote Code...

- AV AC AU C I A
发布: 2015-09-17
修订: 2025-03-08

This Metasploit module exploits a default credential vulnerability in ManageEngine OpManager, where a default hidden account "IntegrationUser" with administrator privileges exists. The account has a default password of "plugin" which can not be reset through the user interface. By log-in and abusing the default administrator's SQL query functionality, it's possible to write a WAR payload to disk and trigger an automatic deployment of this payload. This Metasploit module has been tested successfully on OpManager v11.5 and v11.6 for Windows.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息