CVE-2014-6039
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 69%
from disclosure to weapon0 days
Published on NVDJan 13
1st PoCNov 5
metasploitNov 5
exploitation probability
69%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/43893unverifiedcve_referencepacketstormsecurity.com/files/128996/ManageEngine-EventLog-Analyzer-SQL-Credential-Disclosure.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.