Show filters
52 Total Results
Displaying 21-30 of 52
Sort by:
Attacker Value
Unknown
CVE-2019-19799
Disclosure Date: March 13, 2020 (last updated February 21, 2025)
Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedServlet servlet.
0
Attacker Value
Unknown
CVE-2014-7863
Disclosure Date: February 08, 2020 (last updated February 21, 2025)
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, which allows remote attackers and remote authenticated users to (1) read arbitrary files via the fileName parameter in a copyfile operation or (2) obtain sensitive information via a directory listing in a listdirectory operation to servlet/FailOverHelperServlet.
0
Attacker Value
Unknown
CVE-2019-19800
Disclosure Date: February 06, 2020 (last updated February 21, 2025)
Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.
0
Attacker Value
Unknown
CVE-2019-19475
Disclosure Date: January 10, 2020 (last updated February 21, 2025)
An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is prone to attack due to lack of file permission security. The malicious users who are in “Authenticated Users” group can exploit privilege escalation and modify PostgreSQL configuration to execute arbitrary command to escalate and gain full system privilege user access and rights over the system.
0
Attacker Value
Unknown
CVE-2019-19649
Disclosure Date: August 28, 2019 (last updated November 27, 2024)
Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet function.
0
Attacker Value
Unknown
CVE-2019-19650
Disclosure Date: August 28, 2019 (last updated November 27, 2024)
Zoho ManageEngine Applications Manager before 13640 allows a remote authenticated SQL injection via the Agent servlet agentid parameter to the Agent.java process function.
0
Attacker Value
Unknown
CVE-2019-15105
Disclosure Date: August 16, 2019 (last updated November 27, 2024)
An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the "Execute Program Action(s)" feature.
0
Attacker Value
Unknown
CVE-2019-15104
Disclosure Date: August 16, 2019 (last updated November 27, 2024)
An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the "Execute Program Action(s)" feature.
0
Attacker Value
Unknown
CVE-2017-11557
Disclosure Date: May 23, 2019 (last updated November 27, 2024)
An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to view the list of domain names and usernames used in a company's network environment via a userconfiguration.do?method=editUser request.
0
Attacker Value
Unknown
CVE-2017-11738
Disclosure Date: May 23, 2019 (last updated November 27, 2024)
In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-based Blind SQL Injection attack.
0