peter bassill · operator
$ cve CVE-2015-7387 JSON

CVE-2015-7387 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 80.2% (pctl 100)

Patch early

A public exploit exists.

Description

ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions and execute arbitrary SQL commands via an allowed query followed by a disallowed one in the query parameter to event/runQuery.do, as demonstrated by "SELECT 1;INSERT INTO." Fixed in Build 11200.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS80.19% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2015-09-28
Last modified2026-06-17

Affected (1)

VendorProduct
zohocorpmanageengine eventlog analyzer

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD