Show filters
28 Total Results
Displaying 21-28 of 28
Sort by:
Attacker Value
Unknown
CVE-2019-12537
Disclosure Date: July 11, 2019 (last updated November 27, 2024)
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the SearchN.do search field.
0
Attacker Value
Unknown
CVE-2019-12595
Disclosure Date: July 11, 2019 (last updated November 27, 2024)
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the RCSettings.do rdsName parameter.
0
Attacker Value
Unknown
CVE-2018-17596
Disclosure Date: October 02, 2018 (last updated November 27, 2024)
In Zoho ManageEngine AssetExplorer, a Stored XSS vulnerability was discovered in the 6.2.0 version via the /AssetDef.do ciName or assetName parameter.
0
Attacker Value
Unknown
CVE-2014-5302
Disclosure Date: August 28, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4 allows remote authenticated users to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2014-5301
Disclosure Date: August 28, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4.
0
Attacker Value
Unknown
CVE-2015-2169
Disclosure Date: June 24, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 allows remote attackers to inject arbitrary web script or HTML via a Publisher registry entry, which is not properly handled when the machine is scanned.
0
Attacker Value
Unknown
CVE-2015-5061
Disclosure Date: June 24, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 and earlier allows remote authenticated users with permissions to add new vendors to inject arbitrary web script or HTML via the organizationName parameter to VendorDef.do.
0
Attacker Value
Unknown
CVE-2012-5956
Disclosure Date: December 11, 2012 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine AssetExplorer 5.6 before service pack 5614 allow remote attackers to inject arbitrary web script or HTML via fields in XML asset data to discoveryServlet/WsDiscoveryServlet, as demonstrated by the DocRoot/Computer_Information/output element.
0