SQL injection in ManageEngine Applications Manager - CVE-2017-16850
Published: March 19, 2018 / Updated: August 10, 2020
ManageEngine Applications Manager
Detailed vulnerability description
The vulnerability allows a remote unauthenticated attacker to execute arbitrary SQL commands in web application database.
The weakness exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted input to the showresource.do resourceid parameter and execute arbitrary SQL commands in web application database.