Show filters
20 Total Results
Displaying 11-20 of 20
Sort by:
Attacker Value
Unknown
ManageEngine Applications Manager versions 12 and 13 suffer from remote SQL inj…
Disclosure Date: June 05, 2018 (last updated November 26, 2024)
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /servlet/MenuHandlerServlet, which is vulnerable to SQL injection. The attacker could extract users' password hashes, which are MD5 hashes without salt, and, depending on the database type and its configuration, could also execute operating system commands using SQL queries.
0
Attacker Value
Unknown
CVE-2017-16847
Disclosure Date: November 16, 2017 (last updated November 26, 2024)
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a showPlasmaView action.
0
Attacker Value
Unknown
CVE-2017-16848
Disclosure Date: November 16, 2017 (last updated November 26, 2024)
Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter.
0
Attacker Value
Unknown
CVE-2017-16850
Disclosure Date: November 16, 2017 (last updated November 26, 2024)
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a getResourceProfiles action.
0
Attacker Value
Unknown
CVE-2017-16846
Disclosure Date: November 16, 2017 (last updated November 26, 2024)
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter.
0
Attacker Value
Unknown
CVE-2017-16849
Disclosure Date: November 16, 2017 (last updated November 26, 2024)
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do?method=viewDashBoard forpage parameter.
0
Attacker Value
Unknown
CVE-2017-16851
Disclosure Date: November 16, 2017 (last updated November 26, 2024)
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter.
0
Attacker Value
Unknown
CVE-2017-16543
Disclosure Date: November 05, 2017 (last updated November 26, 2024)
Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.
0
Attacker Value
Unknown
CVE-2017-16542
Disclosure Date: November 05, 2017 (last updated November 26, 2024)
Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request.
0
Attacker Value
Unknown
CVE-2017-5645
Disclosure Date: April 17, 2017 (last updated November 08, 2023)
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
0