HTTP: Zoho ManageEngine ADManager Plus Unrestricted File Upload

This signature detects attempts to exploit a known vulnerability against Zoho ManageEngine ADManager Plus. A successful attack can lead to remote file inclusion.

Extended Description

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

Affected Products

Zohocorp manageengine_admanager_plus

References

CVE: CVE-2021-37926

Short Name
HTTP:CTS:ZOHO-ME-ADMNGR-FU
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
ADManager CVE-2021-37920 CVE-2021-37926 File ManageEngine Plus Unrestricted Upload Zoho
Release Date
03/03/2022
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3646
False Positive
Unknown
Vendors

Zohocorp

CVSS Score

7.5

Found a potential security threat?