漏洞描述
Zoho ManageEngine ADManager Plus through 7180 allows for authenticated users to exploit command injection via Proxy settings.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
hnd3884.github.iohttps://hnd3884.github.io/posts/CVE-2023-29084-Command-injection-in-ManageEngine-ADManager-plus/↗community.grafana.comhttps://community.grafana.com/t/release-notes-v6-3-x/19202↗packetstormsecurity.comhttp://packetstormsecurity.com/files/172755/ManageEngine-ADManager-Plus-Command-Injection.html↗manageengine.comhttps://manageengine.com↗www.manageengine.comhttps://www.manageengine.com/products/ad-manager/admanager-kb/cve-2023-29084.html↗