Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2015-7766Manageengine Opmanager vulnerability

CWE-2644 documents4 sources
Severity
9.0CRITICALNVD
EPSS
77.5%
top 1.01%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedOct 9
Latest updateMay 17

Description

PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions via a comment in the query to api/json/admin/SubmitQuery, as demonstrated by "INSERT/**/INTO."

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 8.0 | Impact: 10.0

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-52f9-rjh6-7wx2: PGSQL:SubmitQuery2022-05-17
CVEList
CVE-2015-7766: PGSQL:SubmitQuery2015-10-09

💥Exploits & PoCs

1
Exploit-DB
ManageEngine OpManager - Remote Code Execution (Metasploit)2015-09-17
CVE-2015-7766 — Manageengine Opmanager vulnerability | cvebase