Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter.Referenceshttps://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2017-16846.htmlhttp://code610.blogspot.com/2017/11/more-sql-injections-in-manageengine.html