CVE-2014-6038
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 73%
from disclosure to weapon0 days
Published on NVDJan 13
1st PoCNov 5
metasploitNov 5
exploitation probability
73%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. Fixed in EventLog Analyzer 10.0 Build 10000.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/43893unverifiedcve_referencepacketstormsecurity.com/files/128996/ManageEngine-EventLog-Analyzer-SQL-Credential-Disclosure.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.