bug-hunting-methodology

1 article
sort: new top best
clear filter
0 8/10

A detailed walkthrough of discovering a critical SQL injection vulnerability (CVE-2019-17602) in Zoho OpManager through white-box analysis by decompiling JAR files, analyzing web.xml servlet mappings, and tracing control flow to identify unsafe dynamic SQL query construction in the getAllMOs method. The vulnerability allows authenticated remote code execution via stacked queries and PostgreSQL UDF commands.

CVE-2019-17602 Zoho OpManager ManageEngine OpManager OPMDeviceDetailsServlet frycos PostgreSQL
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 18 hours ago · details