HTTP: ManageEngine Desktop Central Servlet AddPluginUser Action Admin Account Creation
This signature detects attempts to exploit a known vulnerability against ManageEngine Desktop. A successful exploit can lead to admin account creation.
Extended Description
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action.
Affected Products
Zohocorp desktop_central
References
CVE: CVE-2014-7862
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Zohocorp
7.5