The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://packetstormsecurity.com/files/129769/Desktop-Central-Add-Administrator.html | third party advisory vdb entry issue tracking |
https://github.com/pedrib/PoC/blob/master/advisories/ManageEngine/me_dc9_admin.txt | third party advisory |
http://www.securityfocus.com/bid/71849 | third party advisory vdb entry |
http://www.securityfocus.com/archive/1/534356/100/0/threaded | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/99595 | third party advisory vdb entry issue tracking |
https://www.manageengine.com/products/desktop-central/cve20147862-unauthorized-account-creation.html | third party advisory |
https://www.rapid7.com/db/modules/auxiliary/admin/http/manage_engine_dc_create_admin | third party advisory exploit |
http://seclists.org/fulldisclosure/2015/Jan/2 | mailing list third party advisory issue tracking |