HTTP: Zoho ManageEngine ADManager Plus Proxy Settings Command Injection

This signature detects attempts to exploit a known vulnerability against Zoho ManageEngine ADManager Plus Proxy Settings Command Injection. A successful attack can lead to command injection and arbitrary code execution.

Extended Description

Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.

Affected Products

Zohocorp manageengine_admanager_plus

Short Name
HTTP:CTS:ZOHO-ADMNGR-CMD-INJ
Severity
Major
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
ADManager CVE-2022-42904 CVE-2023-29084 Command Injection ManageEngine Plus Proxy Settings Zoho
Release Date
12/27/2022
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3660
False Positive
Rarely
Vendors

Zohocorp

Found a potential security threat?