mirror of
https://github.com/gobysec/GobyVuls.git
synced 2025-06-20 09:50:49 +00:00
Add CVE-2020-10189
This commit is contained in:
parent
40e8881c1c
commit
606397e482
BIN
ManageEngine/CVE-2020-10189/CVE-2020-10189.gif
Normal file
BIN
ManageEngine/CVE-2020-10189/CVE-2020-10189.gif
Normal file
Binary file not shown.
After Width: | Height: | Size: 281 KiB |
9
ManageEngine/CVE-2020-10189/README.md
Normal file
9
ManageEngine/CVE-2020-10189/README.md
Normal file
@ -0,0 +1,9 @@
|
|||||||
|
# CVE-2020-10189 Zoho ManageEngine Desktop Central 10 getChartImage rce
|
||||||
|
|
||||||
|
Zoho ManageEngine Desktop Central 10 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.
|
||||||
|
|
||||||
|
**[FOFA](https://fofa.so/result?qbase64=YXBwPSJab2hvLU1hbmFnZUVuZ2luZS1EZXNrdG9wIg%3D%3D) query rule**: app="Zoho-ManageEngine-Desktop"
|
||||||
|
|
||||||
|
# Demo
|
||||||
|
|
||||||
|

|
Loading…
x
Reference in New Issue
Block a user