RULE(RULE ID:312087)

Rule General Information
Release Date: 2017-04-13
Rule Name: Manageengine Eventlog Analyzer Runquery Guest User SQL Injection Vulnerability -4 (CVE-2015-7387)
Severity:
CVE ID:
Rule Protection Details
Description: ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions and execute arbitrary SQL commands via an allowed query followed by a disallowed one in the query parameter to event/runQuery.do.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows
Reference: ExploitDB:38173
ExploitDB:38352
Solutions
More advisories have been published on the website, please visit for more suggestions:
https://www.manageengine.com/products/eventlog/release-notes.html