Show filters
67 Total Results
Displaying 1-10 of 67
Sort by:
Attacker Value
Unknown

CVE-2025-23834

Disclosure Date: January 23, 2025 (last updated January 24, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Links/Problem Reporter allows Reflected XSS. This issue affects Links/Problem Reporter: from n/a through 2.6.0.
0
Attacker Value
Unknown

CVE-2025-23833

Disclosure Date: January 16, 2025 (last updated January 17, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RaminMT Links/Problem Reporter allows DOM-Based XSS.This issue affects Links/Problem Reporter: from n/a through 2.6.0.
0
Attacker Value
Unknown

CVE-2024-9459

Disclosure Date: November 05, 2024 (last updated November 07, 2024)
Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in reports module.
Attacker Value
Unknown

CVE-2024-6204

Disclosure Date: August 30, 2024 (last updated September 20, 2024)
Zohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module.
Attacker Value
Unknown

CVE-2024-38872

Disclosure Date: July 26, 2024 (last updated September 12, 2024)
Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the monitoring module.
Attacker Value
Unknown

CVE-2024-38871

Disclosure Date: July 26, 2024 (last updated September 12, 2024)
Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the reports module.
Attacker Value
Unknown

CVE-2021-22508

Disclosure Date: May 17, 2024 (last updated June 06, 2024)
A potential vulnerability has been identified for OpenText Operations Bridge Reporter. The vulnerability could be exploited to inject malicious SQL queries. An attack requires to be an authenticated administrator of OBR with network access to the OBR web application.
0
Attacker Value
Unknown

CVE-2024-4301

Disclosure Date: April 29, 2024 (last updated January 05, 2025)
N-Reporter and N-Cloud, products of the N-Partner, have an OS Command Injection vulnerability. Remote attackers with normal user privilege can execute arbitrary system commands by manipulating user inputs on a specific page.
0
Attacker Value
Unknown

CVE-2024-21775

Disclosure Date: February 16, 2024 (last updated December 21, 2024)
Zoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in report exporting feature.
Attacker Value
Unknown

CVE-2023-6105

Disclosure Date: November 15, 2023 (last updated February 14, 2025)
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.