CVE-2017-16850
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a getResourceProfiles action.
Date published : 2017-11-16
http://code610.blogspot.com/2017/11/more-sql-injections-in-manageengine.html
