GobyVuls/CVE-2022-35405.md
2023-04-13 15:28:07 +08:00

1.4 KiB
Raw Permalink Blame History

ZOHO ManageEngine Password Manager Pro RCE (CVE-2022-35405)

Vulnerability ZOHO ManageEngine Password Manager Pro RCE (CVE-2022-35405)
Chinese name ZOHO ManageEngine Password Manager Pro 远程代码执行漏洞CVE-2022-35405
CVSS core 9.8
FOFA Query (click to view the results directly) banner="Server: PMP" || header="Server: PMP" || banner="Set-Cookie: pmpcc=" || header="Set-Cookie: pmpcc=" || title="ManageEngine Password Manager Pro"
Number of assets affected 672
Description ZOHO ManageEngine Password Manager Pro is a password manager from the American company ZOHO. ZOHO ManageEngine Password Manager Pro versions prior to 12101 and PAM360 prior to 5510 have security vulnerabilities, attackers can execute arbitrary commands to gain server privileges.
Impact ZOHO ManageEngine Password Manager Pro versions prior to 12101 and PAM360 prior to 5510 have security vulnerabilities, attackers can execute arbitrary commands to gain server privileges.