HTTP: Zoho ManageEngine RecoveryManager Plus updateProxySettings Command Injection
This signature detects attempts to exploit a known vulnerability against Zoho ManageEngine RecoveryManager Plus. A successful attack can lead to command injection and arbitrary code execution.
Extended Description
Zoho ManageEngine RecoveryManager Plus before 6070 allows admin users to execute arbitrary commands via proxy settings.
Affected Products
Zohocorp manageengine_recoverymanager_plus
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Zohocorp