Add CVE-2020-10189

This commit is contained in:
tardc 2020-06-23 19:13:21 +08:00
parent 40e8881c1c
commit 606397e482
2 changed files with 9 additions and 0 deletions

Binary file not shown.

After

Width:  |  Height:  |  Size: 281 KiB

View File

@ -0,0 +1,9 @@
# CVE-2020-10189 Zoho ManageEngine Desktop Central 10 getChartImage rce
Zoho ManageEngine Desktop Central 10 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.
**[FOFA](https://fofa.so/result?qbase64=YXBwPSJab2hvLU1hbmFnZUVuZ2luZS1EZXNrdG9wIg%3D%3D) query rule**: app="Zoho-ManageEngine-Desktop"
# Demo
![](CVE-2020-10189.gif)