Required CVE Record Information
Description
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action.
References 8 Total
- http://packetstormsecurity.com/files/129769/Desktop-Central-Add-Administrator.html
- https://github.com/pedrib/PoC/blob/master/advisories/ManageEngine/me_dc9_admin.txt
- securityfocus.com: 71849 vdb-entry
- securityfocus.com: 20141231 [The ManageOwnage Series, part X]: 0-day administrator account creation in Desktop Central mailing-list
- exchange.xforce.ibmcloud.com: desktopcentral-cve20147862-sec-bypass(99595) vdb-entry
- https://www.manageengine.com/products/desktop-central/cve20147862-unauthorized-account-creation.html
- https://www.rapid7.com/db/modules/auxiliary/admin/http/manage_engine_dc_create_admin
- seclists.org: 20150102 [The ManageOwnage Series, part X]: 0-day administrator account creation in Desktop Central mailing-list
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 8 Total
- http://packetstormsecurity.com/files/129769/Desktop-Central-Add-Administrator.html x_transferred
- https://github.com/pedrib/PoC/blob/master/advisories/ManageEngine/me_dc9_admin.txt x_transferred
- securityfocus.com: 71849 vdb-entryx_transferred
- securityfocus.com: 20141231 [The ManageOwnage Series, part X]: 0-day administrator account creation in Desktop Central mailing-listx_transferred
- exchange.xforce.ibmcloud.com: desktopcentral-cve20147862-sec-bypass(99595) vdb-entryx_transferred
- https://www.manageengine.com/products/desktop-central/cve20147862-unauthorized-account-creation.html x_transferred
- https://www.rapid7.com/db/modules/auxiliary/admin/http/manage_engine_dc_create_admin x_transferred
- seclists.org: 20150102 [The ManageOwnage Series, part X]: 0-day administrator account creation in Desktop Central mailing-listx_transferred