Show filters
80 Total Results
Displaying 11-20 of 80
Sort by:
Attacker Value
Unknown
CVE-2023-48654
Disclosure Date: December 25, 2023 (last updated January 04, 2024)
One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset functionality. The escape sequence is: go to the Google ReCAPTCHA section, click on the Privacy link, observe that there is a new browser window, navigate to any website that offers file upload, navigate to cmd.exe from the file explorer window, and launch cmd.exe as NT AUTHORITY\SYSTEM.
0
Attacker Value
Unknown
CVE-2023-6105
Disclosure Date: November 15, 2023 (last updated February 14, 2025)
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.
0
Attacker Value
Unknown
CVE-2023-4003
Disclosure Date: September 27, 2023 (last updated October 08, 2023)
One Identity Password Manager version 5.9.7.1 - An unauthenticated attacker with physical access to a workstation may upgrade privileges to SYSTEM through an unspecified method. CWE-250: Execution with Unnecessary Privileges.
0
Attacker Value
Unknown
CVE-2020-27449
Disclosure Date: August 11, 2023 (last updated October 08, 2023)
Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to execute arbitrary code and steal cookies via crafted JavaScript payload.
0
Attacker Value
Unknown
CVE-2023-25428
Disclosure Date: May 12, 2023 (last updated October 08, 2023)
A DLL Hijacking issue discovered in Soft-o Free Password Manager 1.1.20 allows attackers to create arbitrary DLLs leading to code execution.
0
Attacker Value
Unknown
CVE-2023-2291
Disclosure Date: April 26, 2023 (last updated October 08, 2023)
Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to modify configuration data that would escalate their permissions from that of a low-privileged user to an Administrative user.
0
Attacker Value
Unknown
CVE-2022-47523
Disclosure Date: January 05, 2023 (last updated October 08, 2023)
Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection.
0
Attacker Value
Unknown
CVE-2022-36664
Disclosure Date: December 26, 2022 (last updated October 08, 2023)
Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL parameter.
0
Attacker Value
Unknown
CVE-2022-43672
Disclosure Date: November 12, 2022 (last updated December 22, 2024)
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671.
0
Attacker Value
Unknown
CVE-2022-43671
Disclosure Date: November 12, 2022 (last updated December 22, 2024)
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection.
0