Show filters
62 Total Results
Displaying 21-30 of 62
Sort by:
Attacker Value
Unknown
CVE-2021-41075
Disclosure Date: October 13, 2021 (last updated February 23, 2025)
The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module API.
0
Attacker Value
Unknown
CVE-2021-41288
Disclosure Date: September 30, 2021 (last updated February 23, 2025)
Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.
0
Attacker Value
Unknown
CVE-2020-19554
Disclosure Date: September 21, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in ManageEngine OPManager <=12.5.174 when the API key contains an XML-based XSS payload.
0
Attacker Value
Unknown
CVE-2021-20078
Disclosure Date: April 01, 2021 (last updated February 22, 2025)
Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway component. This allows a remote attacker to remotely delete any directory or directories on the OS.
0
Attacker Value
Unknown
CVE-2020-13818
Disclosure Date: June 04, 2020 (last updated February 21, 2025)
In Zoho ManageEngine OpManager before 125144, when <cachestart> is used, directory traversal validation can be bypassed.
0
Attacker Value
Unknown
CVE-2020-11946
Disclosure Date: April 20, 2020 (last updated February 21, 2025)
Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.
0
Attacker Value
Unknown
CVE-2020-11527
Disclosure Date: April 04, 2020 (last updated November 27, 2024)
In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files.
0
Attacker Value
Unknown
CVE-2020-10541
Disclosure Date: March 13, 2020 (last updated November 27, 2024)
Zoho ManageEngine OpManager before 12.4.179 allows remote code execution via a specially crafted Mail Server Settings v1 API request. This was fixed in 12.5.108.
0
Attacker Value
Unknown
CVE-2014-7863
Disclosure Date: February 08, 2020 (last updated February 21, 2025)
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, which allows remote attackers and remote authenticated users to (1) read arbitrary files via the fileName parameter in a copyfile operation or (2) obtain sensitive information via a directory listing in a listdirectory operation to servlet/FailOverHelperServlet.
0
Attacker Value
Unknown
CVE-2019-17421
Disclosure Date: November 21, 2019 (last updated November 27, 2024)
Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting this file with a malicious payload.
0